01Overview#
Modulon answers patient calls and texts, manages schedules, drafts visit notes, routes refills and results, and runs eligibility, claims and payments for specialty clinics, so it handles protected health information (PHI) every day. Under HIPAA, the clinic is the covered entity and Modulon is its business associate. We are directly responsible for meeting the HIPAA Security Rule, the parts of the Privacy Rule that apply to business associates, and the Breach Notification Rule.
This page explains how we meet each of those rules, what stays the clinic's responsibility, and the documentation we provide to support a clinic's own compliance program.
02A note on HIPAA certification#
There is no official HIPAA certification. The Department of Health and Human Services does not certify or endorse vendors, and a "HIPAA certified" badge reflects only a private assessment. What matters is whether a vendor signs a Business Associate Agreement, maintains the safeguards the rules require, and can show its work. We do all three, and we will walk your compliance officer through any part of our program.
03Business Associate Agreements#
- We sign our Business Associate Agreement with every clinic before any PHI is shared, including during a pilot. We will also review a clinic's own template.
- Every subcontractor that handles PHI for us has signed a Business Associate Agreement that holds it to the same restrictions. They are listed on our subprocessors page, and clinics get 30 days' notice before a new one handles PHI.
04Privacy Rule#
- Permitted uses only. We use and disclose PHI only to provide the services in our agreement with the clinic, for our own proper management, and as required by law.
- Minimum necessary. Each part of the platform, each request to an AI model, and each person on our team can reach only the PHI their task requires.
- No sale, no marketing. We never sell PHI or use it for marketing, and we do not use it to train general-purpose AI models.
- Patient rights. We help clinics answer requests for access, amendment and an accounting of disclosures, and forward any request we receive directly to the clinic within five business days.
- United States only. PHI is stored and processed only in the United States.
05Security Rule#
Administrative safeguards
- A designated security officer and written security policies, reviewed every year.
- A risk analysis every year and after major changes, with a tracked plan to reduce each risk it finds.
- HIPAA and security training for every employee when they join and every year after.
- Background checks and confidentiality agreements for everyone with access to PHI.
- Quarterly reviews of who has access to what, and a sanctions policy for violations.
- A written incident response plan and contingency plan, each tested every year.
Physical safeguards
- PHI is hosted in U.S. data centers operated by Google Cloud, with audited physical controls.
- No PHI is stored on employee laptops; company devices are encrypted and centrally managed.
Technical safeguards
- Encryption of PHI in transit with TLS 1.2 or higher, and at rest with AES-256.
- Unique user accounts, role-based access, multi-factor authentication and automatic sign-out.
- A complete audit trail of every action, by staff or by the AI, kept for at least six years.
- Integrity controls, and encrypted backups that are restored regularly to prove they work.
Our Security page covers these controls in more detail.
06Breach Notification Rule#
If we discover a breach of unsecured PHI, we notify the affected clinic without unreasonable delay, and no later than ten business days after discovering it, well inside HIPAA's 60-day limit. Our notice identifies the patients affected and what happened, and we provide everything the clinic needs to notify patients, HHS and, where required, the media. Where we or our subcontractors caused the breach, we cover the reasonable cost of the notifications the law requires.
07AI and PHI#
- Every AI provider that processes PHI for Modulon has signed a Business Associate Agreement with us.
- Our AI providers do not retain PHI or use it to train their models.
- The AI acts only within the policies each clinic sets, which are enforced in software, and hands anything else to staff.
- AI-drafted clinical content, such as visit notes, is reviewed and signed by the provider before it enters the record, and nothing clinical reaches a patient without a clinician's approval.
- Patients are told when they are talking to an automated assistant, and can ask for a person at any time.
08Other health privacy laws#
Substance use disorder records
Behavioral health practices may hold records protected by 42 C.F.R. Part 2. Modulon protects those records as PHI under our Business Associate Agreement, will sign the additional terms Part 2 requires, and supports the clinic in honoring the consents those records carry. Clinics should tell us before connecting Modulon to Part 2 records.
State law
Some states set stricter rules for certain health information, such as mental health, HIV status, genetic testing and reproductive care, or for recording calls. Modulon lets clinics restrict how such information is handled and disclosed, and follows the clinic's instructions where state law gives patients more protection than HIPAA.
10Documentation for your compliance file#
On request, we provide clinics with:
- Our Business Associate Agreement, signed before any PHI is shared.
- Our current list of subprocessors.
- A completed security questionnaire, or answers to your own.
- A summary of our most recent risk analysis and independent security testing.
- Audit log exports for your own reviews and accountings of disclosures.
Write to hello@modulonhealth.com and we will reply within two business days.
Questions about this page? Write to hello@modulonhealth.com.