1. Overview
Medonix processes protected health information (PHI) on behalf of U.S. healthcare providers under the Health Insurance Portability and Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH). Our compliance program aligns to the HIPAA Privacy, Security, and Breach Notification Rules and is operationally integrated with our SOC 2 Type II and HITRUST CSF programs.
2. Our role
When customers engage Medonix to process PHI, we act as a business associate under 45 C.F.R. §160.103. Every engagement is governed by a signed Business Associate Agreement that obligates us to (a) use PHI only for permitted purposes, (b) implement HIPAA-compliant safeguards, (c) report security incidents and breaches, and (d) bind any subcontractors handling PHI to equivalent terms. See our standard BAA.
3. Administrative safeguards (45 C.F.R. §164.308)
- Documented information-security program with executive ownership and quarterly board review.
- Workforce training on HIPAA, PHI handling, and security awareness within 30 days of hire and annually thereafter.
- Role-based access controls with least-privilege defaults; quarterly access reviews.
- Background checks on all personnel with PHI access.
- Incident-response program with documented runbooks and 24/7 on-call.
- Annual HIPAA risk analysis and risk-management plan with tracked remediation.
4. Physical safeguards (45 C.F.R. §164.310)
- All production infrastructure runs in HIPAA-eligible cloud regions of major providers (AWS / GCP / Azure) with the corresponding cloud-provider BAA in place.
- No on-premise servers handling PHI in Medonix-controlled facilities.
- Workforce devices managed via MDM with full-disk encryption, automated patching, and remote-wipe capability.
- Physical-access controls at the cloud provider level meet SOC 2 / ISO 27001 attestation standards.
5. Technical safeguards (45 C.F.R. §164.312)
- Encryption in transit: TLS 1.2 minimum (TLS 1.3 preferred) for all data movement.
- Encryption at rest: AES-256 for all PHI stores (databases, object storage, backups).
- Authentication: SSO with MFA enforced for all workforce access. Customer access is configurable per organization with SAML 2.0 / OIDC integration.
- Audit logging: Comprehensive PHI access logging with tamper-evident storage and retention aligned to applicable record-retention laws.
- Integrity: Cryptographic hashing on backups and audit logs; regular restoration testing.
- Vulnerability management: Continuous scanning, third-party penetration testing annually, and a public bug-bounty program.
6. Breach notification
Medonix maintains a documented breach-notification program aligned to 45 C.F.R. §164.400-414. On confirmed breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and no later than 15 calendar days after discovery (earlier than the 60-day statutory ceiling) and provide all information required for the covered entity to fulfill its own notification obligations.
7. Resources
Customers and prospects can request our HIPAA control documentation, third-party audit reports, and the standard BAA via [email protected]. Documentation is available under NDA prior to contract sign for evaluation purposes.