HIPAA Compliance Statement

This statement outlines the commitment of On-Call.ai to complying with the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Our AI automation solutions are designed to handle, process, and store Protected Health Information (PHI) in a secure and compliant manner. We understand the critical importance of protecting patient privacy and data security, and we have implemented robust technical, administrative, and physical safeguards to ensure the confidentiality, integrity, and availability of all PHI.

Our Commitment to HIPAA

On-Call.ai acknowledges its role as a Business Associate under HIPAA when providing services to Covered Entities. We are dedicated to the following principles:

Data Security: We use industry-standard encryption protocols, both in transit and at rest, to secure all PHI. Our systems are built with security-by-design principles, including access controls, authentication, and regular vulnerability scanning.

Privacy and Confidentiality: We only access, use, and disclose PHI as permitted by our Business Associate Agreement (BAA) and as required by law. Our employees receive mandatory training on HIPAA regulations and privacy best practices.

Data Integrity: Our systems are designed to maintain the accuracy and consistency of PHI. We have implemented auditing and logging mechanisms to track all access and modifications to patient data, ensuring a clear audit trail.

Availability: We have implemented comprehensive backup and disaster recovery plans to ensure that PHI remains accessible and recoverable in the event of a system failure or data loss.


Safeguards Implemented

We have established and maintain the following safeguards in accordance with the HIPAA Security Rule:

Administrative Safeguards:

  • Risk Analysis and Management: We conduct regular risk assessments to identify and mitigate potential threats and vulnerabilities to PHI.
  • HIPAA Policies and Procedures: We have detailed policies and procedures governing the handling of PHI, including incident response and breach notification protocols.
  • Workforce Training: All personnel with access to PHI are trained on HIPAA regulations and our internal security policies.

Physical Safeguards:

  • Access Control: Our data centers and physical infrastructure are secured with physical access controls, including surveillance and visitor logs.
  • Device and Media Control: We have policies for the secure disposal of electronic media and devices containing PHI.

Technical Safeguards:

  • Access Control: We use role-based access controls to limit access to PHI to authorized personnel only.
  • Encryption: All PHI is encrypted at rest and in transit using strong cryptographic standards.
  • Audit Controls: Our systems automatically record all activities involving PHI, providing a detailed audit trail.

Business Associate Agreements (BAAs)

On-Call.ai requires a signed Business Associate Agreement (BAA) with all Covered Entities. The BAA defines the permissible uses and disclosures of PHI, outlines our security obligations, and specifies our responsibilities in the event of a data breach. We will not begin any services involving PHI until a fully executed BAA is in place.

For questions regarding our HIPAA compliance, please contact info@on-call.ai.

ON-CALL.AI

Smarter Answering.

HIPAA Compliant.

Backed by 30 Years.

Quick Links

About Us

Products and Services

Contact Us

Terms and Conditions

Privacy Policy

HIPAA Statement