HIPAA Compliance
InfoSec, LLC operates under a comprehensive HIPAA compliance program. We sign a Business Associate Agreement with every client before any PHI is exchanged. All access to PHI is role-based, logged, and reviewed on a quarterly basis.
Privacy & Security
Protected health information is the most sensitive data we handle. Our systems, our team, and our processes are designed around that reality.
InfoSec, LLC operates under a comprehensive HIPAA compliance program. We sign a Business Associate Agreement with every client before any PHI is exchanged. All access to PHI is role-based, logged, and reviewed on a quarterly basis.
All PHI is transmitted over TLS 1.3 encrypted channels. At rest, data is stored in U.S.-based, SOC 2 audited facilities with AES-256 encryption. We never store PHI on local workstations or removable media.
Every team member completes annual HIPAA training and is granted access only to the specific client engagements they are assigned to. Privileged access requires multi-factor authentication and is reviewed monthly.
We maintain a documented incident response plan with breach notification procedures that meet or exceed HIPAA Breach Notification Rule timelines. Clients are notified within 24 hours of any suspected incident affecting their data.
Every chart accessed, every code applied, and every query sent is logged with timestamp, user, and action. Audit trails are retained for a minimum of six years and made available to clients on request.
We do not subcontract or offshore any clinical documentation work. Every coder, CDIP, and scribe is a U.S.-based InfoSec, LLC employee.