Legal

HIPAA Notice of Privacy Practices

How Medicare EHR handles Protected Health Information when acting as a business associate to covered entities — including permitted uses, safeguards, breach notification, and your rights.

Effective date: June 7, 2026

Business Associate Notice

This document supplements — and does not replace — your organization's own Notice of Privacy Practices or Business Associate Agreement with Medicare EHR.

  • HIPAA Privacy & Security Rule alignment
  • BAA available for enterprise customers
  • Breach notification per 45 C.F.R. § 164.410

1. Introduction

This HIPAA Notice describes how Medicare EHR ("we," "us," or "our") handles Protected Health Information ("PHI") when we provide electronic health record and clinic operations services to healthcare organizations.

This notice is provided for transparency. When we process PHI on behalf of a covered entity (such as a hospital, clinic, or practice), we act as a business associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH).

2. Our Role as a Business Associate

A covered entity determines the purposes for which PHI is used. We process PHI only to perform services for the covered entity, as instructed in our agreement with that organization, or as required by law.

We do not use or disclose PHI for our own marketing purposes. Workforce members with access to PHI are authorized based on role and tenant scope.

3. Permitted Uses and Disclosures of PHI

Subject to the Business Associate Agreement (BAA) with each customer, we may use and disclose PHI for the following purposes:

  • Providing, maintaining, and supporting the EHR platform and related services contracted by the covered entity
  • Enabling clinical, operational, billing, and patient engagement workflows authorized by the covered entity
  • Creating de-identified or limited data sets only when permitted by the BAA and applicable law
  • Complying with legal process, court orders, or mandatory reporting obligations
  • Reporting violations of our policies or suspected unlawful activity to appropriate authorities when required

4. Safeguards We Maintain

We implement administrative, physical, and technical safeguards designed to meet the requirements of the HIPAA Security Rule, including:

  • Administrative safeguards: workforce access authorization, security management, and incident procedures
  • Physical safeguards: reliance on secure data-center providers with controlled facility access for hosted infrastructure
  • Technical safeguards: AES-256-GCM encryption for designated sensitive fields, role-based access control, multi-factor authentication, unique user identification, and automatic logoff via session management
  • Audit controls: activity logging with contextual metadata; separate security event logging for authentication failures and lockouts
  • Integrity controls: validated server actions and tenant-scoped database queries to reduce unauthorized alteration
  • Transmission security: encrypted connections (TLS) between clients and our services in production deployments

5. Minimum Necessary Standard

We configure the platform so that users receive access to PHI based on assigned roles (for example, reception, nursing, clinical, pharmacy, lab, finance, and administration). Covered entities are responsible for provisioning accounts and reviewing access periodically.

6. Subcontractors and Service Providers

We may engage subprocessors (such as cloud hosting, email delivery, payment, observability, or telehealth providers) that create, receive, maintain, or transmit PHI on our behalf. We require subprocessors that handle PHI to agree to appropriate restrictions and safeguards consistent with HIPAA.

A list of material subprocessors is available to enterprise customers upon request. Customers should not send PHI to subprocessors outside the contracted platform without authorization.

7. Individual Rights

Under HIPAA, individuals have rights regarding their PHI, including rights of access, amendment, and accounting of disclosures in certain circumstances. Because we act as a business associate, requests to exercise these rights should generally be directed to the covered entity that maintains the individual's record of care.

We will assist our customers in responding to such requests as required by our BAA and applicable law.

8. Breach Notification

In the event of a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and in accordance with 45 C.F.R. § 164.410 and the terms of the BAA.

Notification will include, to the extent known, the identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed, together with any additional information required by law or contract to support the covered entity's breach notification obligations to individuals and regulators.

9. Business Associate Agreement

Enterprise customers may execute a Business Associate Agreement with us before or during onboarding. The BAA defines permitted uses, safeguards, subcontractor requirements, termination provisions, and return or destruction of PHI.

To request a BAA or security documentation package, contact support@medicare-ehr.sl.

10. Data Retention and Return

We retain PHI for the period necessary to provide services under the customer agreement. Upon termination, we will return or destroy PHI as specified in the BAA, subject to legal retention requirements and backup media constraints described in the agreement.

Customers may configure backup retention policies within the platform's administrative backup settings.

11. Changes to This Notice

We may update this notice to reflect changes in law, regulatory guidance, or our services. The effective date at the top of this page will be revised when material changes are made. Continued use of the platform after notice of an update constitutes acknowledgment of the revised notice where permitted by contract.

12. Complaints

Individuals who believe their privacy rights have been violated may file a complaint with their healthcare provider (the covered entity) or with the U.S. Department of Health and Human Services Office for Civil Rights.

We prohibit retaliation against anyone for filing a complaint or participating in an investigation.

13. Contact Information

Privacy and HIPAA inquiries: support@medicare-ehr.sl

Postal inquiries: Available to enterprise customers upon request.

For product security controls and technical safeguards, visit the Security page linked below.

Need a Business Associate Agreement?

Contact us to request a BAA, subprocessors list, or security documentation for your compliance review.

Request BAA