HIPAA Compliance

How Modulon meets its obligations as a business associate, and how we support each clinic's own HIPAA program.

Last updated

01Overview#

Modulon answers patient calls and texts, manages schedules, drafts visit notes, routes refills and results, and runs eligibility, claims and payments for specialty clinics, so it handles protected health information (PHI) every day. Under HIPAA, the clinic is the covered entity and Modulon is its business associate. We are directly responsible for meeting the HIPAA Security Rule, the parts of the Privacy Rule that apply to business associates, and the Breach Notification Rule.

This page explains how we meet each of those rules, what stays the clinic's responsibility, and the documentation we provide to support a clinic's own compliance program.

02A note on HIPAA certification#

There is no official HIPAA certification. The Department of Health and Human Services does not certify or endorse vendors, and a "HIPAA certified" badge reflects only a private assessment. What matters is whether a vendor signs a Business Associate Agreement, maintains the safeguards the rules require, and can show its work. We do all three, and we will walk your compliance officer through any part of our program.

03Business Associate Agreements#

  • We sign our Business Associate Agreement with every clinic before any PHI is shared, including during a pilot. We will also review a clinic's own template.
  • Every subcontractor that handles PHI for us has signed a Business Associate Agreement that holds it to the same restrictions. They are listed on our subprocessors page, and clinics get 30 days' notice before a new one handles PHI.

04Privacy Rule#

  • Permitted uses only. We use and disclose PHI only to provide the services in our agreement with the clinic, for our own proper management, and as required by law.
  • Minimum necessary. Each part of the platform, each request to an AI model, and each person on our team can reach only the PHI their task requires.
  • No sale, no marketing. We never sell PHI or use it for marketing, and we do not use it to train general-purpose AI models.
  • Patient rights. We help clinics answer requests for access, amendment and an accounting of disclosures, and forward any request we receive directly to the clinic within five business days.
  • United States only. PHI is stored and processed only in the United States.

05Security Rule#

Administrative safeguards

  • A designated security officer and written security policies, reviewed every year.
  • A risk analysis every year and after major changes, with a tracked plan to reduce each risk it finds.
  • HIPAA and security training for every employee when they join and every year after.
  • Background checks and confidentiality agreements for everyone with access to PHI.
  • Quarterly reviews of who has access to what, and a sanctions policy for violations.
  • A written incident response plan and contingency plan, each tested every year.

Physical safeguards

  • PHI is hosted in U.S. data centers operated by Google Cloud, with audited physical controls.
  • No PHI is stored on employee laptops; company devices are encrypted and centrally managed.

Technical safeguards

  • Encryption of PHI in transit with TLS 1.2 or higher, and at rest with AES-256.
  • Unique user accounts, role-based access, multi-factor authentication and automatic sign-out.
  • A complete audit trail of every action, by staff or by the AI, kept for at least six years.
  • Integrity controls, and encrypted backups that are restored regularly to prove they work.

Our Security page covers these controls in more detail.

06Breach Notification Rule#

If we discover a breach of unsecured PHI, we notify the affected clinic without unreasonable delay, and no later than ten business days after discovering it, well inside HIPAA's 60-day limit. Our notice identifies the patients affected and what happened, and we provide everything the clinic needs to notify patients, HHS and, where required, the media. Where we or our subcontractors caused the breach, we cover the reasonable cost of the notifications the law requires.

07AI and PHI#

  • Every AI provider that processes PHI for Modulon has signed a Business Associate Agreement with us.
  • Our AI providers do not retain PHI or use it to train their models.
  • The AI acts only within the policies each clinic sets, which are enforced in software, and hands anything else to staff.
  • AI-drafted clinical content, such as visit notes, is reviewed and signed by the provider before it enters the record, and nothing clinical reaches a patient without a clinician's approval.
  • Patients are told when they are talking to an automated assistant, and can ask for a person at any time.

08Other health privacy laws#

Substance use disorder records

Behavioral health practices may hold records protected by 42 C.F.R. Part 2. Modulon protects those records as PHI under our Business Associate Agreement, will sign the additional terms Part 2 requires, and supports the clinic in honoring the consents those records carry. Clinics should tell us before connecting Modulon to Part 2 records.

State law

Some states set stricter rules for certain health information, such as mental health, HIV status, genetic testing and reproductive care, or for recording calls. Modulon lets clinics restrict how such information is handled and disclosed, and follows the clinic's instructions where state law gives patients more protection than HIPAA.

09Shared responsibility#

HIPAA compliance is shared between Modulon and each clinic:

AreaModulonThe clinic
AgreementsSigns a BAA with the clinic and with every subcontractor that handles PHISigns the BAA before sharing PHI
Platform securitySecures the infrastructure, application and dataKeeps its own devices, network and connected systems secure
User accessProvides roles, MFA, automatic sign-out and audit logsGrants the right roles and removes departing staff
PoliciesEnforces the policies the clinic configuresSets policies that match its own procedures
Clinical contentDrafts notes and routes refills and results for reviewReviews and signs anything clinical before it is used
Patient communicationsDiscloses the AI, honors opt-outs and records consentObtains consent and publishes its Notice of Privacy Practices
RecordingAnnounces call recording and stores recordings securelyObtains patient consent before the AI note taker records a visit
BreachesNotifies the clinic and supports its responseNotifies patients and HHS

10Documentation for your compliance file#

On request, we provide clinics with:

  • Our Business Associate Agreement, signed before any PHI is shared.
  • Our current list of subprocessors.
  • A completed security questionnaire, or answers to your own.
  • A summary of our most recent risk analysis and independent security testing.
  • Audit log exports for your own reviews and accountings of disclosures.

Write to hello@modulonhealth.com and we will reply within two business days.

Questions about this page? Write to hello@modulonhealth.com.