Hospice runs on trust, from families, from referral sources, from CMS. Every HospiNotes engagement runs under a signed Business Associate Agreement from day one, with encryption, least privilege access and complete audit logging on every chart we touch. No exceptions.
Four pillars that make "HIPAA compliant" more than a checkbox.
Access to PHI is scoped to the minimum each role needs and enforced with multi factor authentication. When a team member's role changes or ends, access changes with it. Immediately, not at the next review cycle.
Every interaction with PHI is logged and monitored, and our environment is continuously watched for anomalies. If something ever looked wrong, you'd hear it from us first, with a clear breach notification protocol aligned to HIPAA timelines.
We'll walk your compliance team through our BAA, encryption, access controls and incident response plan, so you can say yes with confidence.
The answers your compliance officer will want.