Business Associate Agreement (BAA) Ready
Smart HMS signs standard and custom Business Associate Agreements (BAAs) with all covered healthcare entities in the United States and international equivalents. Request an executable BAA by contacting compliance@smarthms.com.
Security & Privacy Rules
Full implementation of administrative, physical, and technical safeguards for ePHI.
Data Protection by Design
Strict processor responsibilities, DPA execution, and zero unauthorized data profiling.
Cryptographic Security
Hardware-grade encryption for all database volumes, backups, and inter-service channels.
Operational Trust
Continuous monitoring of security, confidentiality, and high-availability controls.
1. HIPAA Compliance & Business Associate Agreement (BAA)
Under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act:
- Smart HMS acts as a Business Associate to covered healthcare entities.
- We execute a formal Business Associate Agreement (BAA) with every covered entity before any live electronic Protected Health Information (ePHI) is ingested or processed.
- We obligate all down-stream hosting providers and cloud vendors to execute equivalent BAAs, ensuring an unbroken chain of custody and legal accountability.
2. Technical Safeguards (45 CFR § 164.312)
Smart HMS implements the full suite of HIPAA technical safeguards:
- Unique User Identification: Every staff member is assigned a distinct, non-shared identity with granular role permissions.
- Automatic Logoff: Client interfaces automatically lock following a configurable period of terminal inactivity (default 15 minutes) to protect unattended screens.
- Encryption & Decryption: ePHI is encrypted using AES-256 at rest and TLS 1.3 in transit. Database keys are managed through secure Hardware Security Modules (HSMs) with regular automated key rotation.
- Transmission Security: All API communications enforce HTTPS with Perfect Forward Secrecy (PFS) and preloaded HSTS headers.
3. Administrative Safeguards
Technical controls are paired with comprehensive institutional policies:
- Security Management Process: Annual risk assessments and continuous vulnerability scanning against OWASP Top 10 vectors.
- Workforce Training: All engineering and support personnel complete mandatory annual HIPAA and data security training.
- Sanction Policy: Strict internal disciplinary policies enforce zero tolerance for unauthorized ePHI inspection.
4. Physical & Cloud Infrastructure Safeguards
Our production databases and microservices reside in Tier IV data centres (AWS / GCP) equipped with biometric perimeter security, 24/7 armed physical surveillance, redundant power generators, and multi-zone disaster mitigation.
5. Immutable Audit Trails & Cryptographic Stamping
Every clinical record view, modification, prescription issuance, laboratory dispatch, and billing transaction generates an immutable audit record:
6. GDPR & International Data Sovereignty
For European and multinational healthcare organizations, Smart HMS complies with GDPR principles:
- Data Minimization: Only fields strictly necessary for hospital operations and patient care are captured.
- Right to Rectification: Authorized clinicians can amend erroneous medical notes with full transparent revision histories.
- Data Residency: Customers can select their preferred geographic cloud region (US, EU, UK, Middle East, APAC) to satisfy domestic healthcare sovereignty mandates.
7. Incident Response & Breach Notification
In the unlikely event of a verified security incident or unauthorized disclosure of ePHI:
- Smart HMS will notify affected Customers within 72 hours of confirmation, well within the HIPAA 60-day threshold and GDPR 72-hour requirement.
- The notification will provide a comprehensive description of the incident, categories of ePHI involved, affected patient identifiers, immediate remedial steps taken, and recommendations for Customer mitigation.
8. Standards, Audits & Inquiries
For questions regarding our third-party penetration test reports, SOC 2 Type II audit summaries, or custom security questionnaires:
Direct Inquiries: compliance@smarthms.com
Security Hotline: security@smarthms.com