HIPAA Compliance & Security Policy
Last updated: July 26, 2026
1. Executive Overview & Commitment
Health Align (referred to here as "Health Align", "we", "us", or "our") is dedicated to maintaining the absolute security, confidentiality, and integrity of Protected Health Information (PHI) and electronic Protected Health Information (ePHI). Our clinical operating systems are built with compliance, structural reliability, and enterprise-grade privacy at their core. We recognize that healthcare information requires the highest tier of security infrastructure, and we have aligned our administrative, physical, and technical operations with the statutory requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health Act (HITECH), and their corresponding regulations.
This document provides a highly detailed explanation of the defensive layers, technical mechanisms, organizational policies, and audit procedures implemented across our systems. We act as a Business Associate for Covered Entities (such as clinics, doctors, hospitals, and pharmacies) under the legal boundaries defined by Business Associate Agreements (BAAs).
2. Technical Safeguards (45 CFR § 164.312)
Our software architecture utilizes state-of-the-art security patterns to prevent unauthorized access, manipulation, interception, or deletion of sensitive health records.
2.1 Encryption in Transit and at Rest
All communication channels between client browsers, medical mobile apps, and our database systems are strictly routed via Hypertext Transfer Protocol Secure (HTTPS) using Transport Layer Security (TLS 1.3) protocol configurations. We enforce HTTP Strict Transport Security (HSTS) to prevent downgrade attacks.
All PHI stored within our databases, including medical prescriptions, patient records, clinical history, and laboratory documents, is encrypted at rest using the Advanced Encryption Standard (AES) with 256-bit key length. Encryption keys are managed and rotated programmatically using isolated Key Management Services (KMS) featuring strict multi-layer access boundaries.
2.2 Access Controls & Authorization
To ensure that only authorized personnel have access to patient records, Health Align implements role-based access control (RBAC):
- Unique User Identification: Every medical professional, receptionist, administrator, and clinical staff member is assigned a unique identifier. Sharing of accounts is strictly prohibited.
- Automatic Logoffs: Active user sessions automatically terminate after 15 minutes of inactivity to prevent physical terminal exposure.
- Emergency Access Procedure: In life-threatening emergencies, designated medical professionals can utilize a structured "break-glass" override protocol to access necessary records, triggering automatic high-priority alerts to system compliance officers.
2.3 Integrity Controls and Audit Logging
Data modification history is fully recorded. We write structural hash checks to verify that data has not been altered, tampered with, or corrupted during transmission or storage. System audit logs run constantly, recording:
- Exact timestamp of every write, read, modification, or deletion request.
- IP address, browser user-agent, session identifiers, and user account metadata of the requester.
- Identified record keys involved in the transaction.
These logs are stored on write-once-read-many (WORM) storage environments, preventing deletion or tampering of audit trails even by root database administrators.
3. Physical Safeguards (45 CFR § 164.310)
Health Align relies on top-tier cloud architecture with physical data centers that strictly enforce rigorous hardware protection parameters.
3.1 Data Center Security
Our hosting facilities implement multi-tier physical perimeter controls, including biometrics, 24/7 video monitoring, security guard checkpoints, and locked equipment enclosures. Physical access is granted strictly on a least-privilege basis to verified infrastructure specialists.
3.2 Workstation & Device Security
Our developers, operators, and support specialists access the system infrastructure using corporate-managed hardware. These devices utilize full-disk encryption, active mobile device management (MDM) policies, automatically updating anti-malware programs, and mandatory secure VPN tunnels.
4. Administrative Safeguards (45 CFR § 164.308)
No technical architecture is complete without operational discipline. Health Align enforces strict corporate management standards.
4.1 Security Management & Risk Analysis
We conduct a comprehensive annual Security Risk Assessment (SRA) to identify vulnerabilities, assess risk potential, and implement structural security controls. Penetration testing is regularly performed by certified third-party cybersecurity firms.
4.2 Employee Training & Security Awareness
Every Health Align employee undergoes mandatory HIPAA compliance training upon hiring, followed by recurrent annual refresher courses. Our teams are trained in data handling protocols, social engineering defenses, phishing identification, and immediate incident reporting.
4.3 Incident Response & Breach Notification Policy
In the unlikely event of a security incident or a suspected data breach, our Incident Response Team (IRT) is activated immediately. If a breach of unsecured PHI is confirmed, we comply fully with the HIPAA Breach Notification Rule (45 CFR §§ 164.400-414), notifying affected covered entities, patients, the Department of Health and Human Services (HHS), and media outlets where legally required within the statutory timelines.
5. Business Associate Agreements (BAAs)
Health Align operates under Business Associate Agreements with our clinical clients. We ensure that our subprocessors, third-party database systems, and integration components also sign binding BAAs, maintaining a complete, legal chain of accountability.
6. Compliance Contact Information
For questions regarding our security architecture, audit reports, BAAs, or to report a security concern, contact our Security and HIPAA Officer at:
Health Align Security Office
Email: security@healthalign.in
Helpline: +91 95316 54447