We’ve migrated our documentation to a new site, which means some URLs have changed. If you hit a broken link, submit a support ticket.
Compliance Center
English French
English French

HIPAA/HITECH

What does it mean?

The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a federal law that required the creation of national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. The US Department of Health and Human Services (HHS) issued the HIPAA Privacy Rule to implement the requirements of HIPAA. The HIPAA Security Rule protects a subset of information covered by the Privacy Rule.

The Privacy Rule standards address the use and disclosure of individuals' health information (known as protected health information or PHI) by entities subject to the Privacy Rule. These individuals and organizations are called "covered entities."

The following types of individuals and organizations are subject to the Privacy Rule and considered covered entities:

  1. Healthcare providers: Every healthcare provider, regardless of size of practice, who electronically transmits health information in connection with certain transactions. These transactions include:

    • Claims

    • Benefit eligibility inquiries

    • Referral authorization requests

    • Other transactions for which HHS has established standards under the HIPAA Transactions Rule.

  2. Health plans which include:

    • Health, dental, vision, and prescription drug insurers

    • Health maintenance organizations (HMOs)

    • Medicare, Medicaid, Medicare+Choice, and Medicare supplement insurers

    • Long-term care insurers (excluding nursing home fixed-indemnity policies)

    • Employer-sponsored group health plans

    • Government- and church-sponsored health plans

    • Multi-employer health plans

      Exception: A group health plan with fewer than 50 participants that is administered solely by the employer that established and maintains the plan is not a covered entity.

  3. Healthcare clearinghouses: Entities that process nonstandard information they receive from another entity into a standard (i.e., standard format or data content), or vice versa. In most instances, healthcare clearinghouses will receive individually identifiable health information only when they are providing these processing services to a health plan or healthcare provider as a business associate.

  4. Business associates: A person or organization (other than a member of a covered entity's workforce) using or disclosing individually identifiable health information to perform or provide functions, activities, or services for a covered entity. These functions, activities, or services include:

    • Claims processing

    • Data analysis

    • Utilization review

    • Billing

While the HIPAA Privacy Rule safeguards PHI, the Security Rule protects a subset of information covered by the Privacy Rule. This subset is all individually identifiable health information a covered entity creates, receives, maintains, or transmits in electronic form. This information is called electronic protected health information, or ePHI. The Security Rule does not apply to PHI transmitted orally or in writing.

To comply with the HIPAA Security Rule, all covered entities must:

  • Ensure the confidentiality, integrity, and availability of all ePHI

  • Detect and safeguard against anticipated threats to the security of the information

  • Protect against anticipated impermissible uses or disclosures that are not allowed by the rule

  • Certify compliance by their workforce

Covered entities should rely on professional ethics and best judgment when considering requests for these permissive uses and disclosures. The HHS Office for Civil Rights enforces HIPAA rules, and all complaints should be reported to that office. HIPAA violations may result in civil monetary or criminal penalties.

Piano falls under the Business associates group of 'covered entities' when a client collects, processes PHI and/or ePHI data and transfers that data to Piano.

What Piano product is covered?

How do we comply?

Piano has implemented Administrative, Technical and Physical controls to protect PHI and ePHI data. These controls are specified in the Piano Software Group Health Plan.

Administrative controls ensure protection of PHI and ePHI information in compliance with security standards. Such standards are discussed and selected based on the executive management decisions. Piano Software established an Information security management system according to ISO 27001 and is complimented by PCI DSS standards.

Piano Software is committed to protecting its information and that of its clients. To accomplish this Piano Software has established an Information Security Management System (ISMS) in accordance with ISO/IEC 27001:2022 as well as contractual agreements and regulatory requirements. This ISMS applies to Piano Software's cloud-based service software development, support and operations for the management of risk associated with a secure client data environment, whether the data is at rest or in transmission. Controls covering the security of Client data are defined within Master services agreements (MSA) with Clients as well as Data processing agreements that are part of the MSA. Piano Software established Group data protection policy, Intragroup data processing agreements, Binding corporate Rules and Platform privacy policy.

Physical controls ensure confidentiality, integrity and availability of PHI and ePHI data stored in physical premises. Access to facilities must be physically restricted with access granted to those employees, contingent workers and vendors who have legitimate business responsibilities within the facility. Piano Software does not store or collect PHI or ePHI data at its office premises. Piano Software uses mainly AWS Managed services infrastructure as well as Snowflake. Physical controls implemented by these providers are reviewed on an annual basis by the Information security team.

Piano Software's Information security policy covers all areas and implemented technical controls from ISO 27001:2022 Annex A including segregation of duties, human resource security, asset management, access control requirements, cryptographic controls, physical security, operations security, network security, secure development lifecycle, supplier relationship policy, incident management, business continuity and disaster recovery and compliance with legislation and requirements.

Certification

On July 10th 2023 we received Type 1 HIPAA/ HITECH Attestation of Compliance.

The health information security program governing the Analytical and Piano Subscriptions Software System (Piano Analytics, Piano Composer, Piano Management + Billing, Identity Management, Piano ESP) complied with applicable requirements of HIPAA and HITECH. The criteria we used in making this assertion were that:

  • Management determined the applicable controls (the "controls") included in the health information security program

  • The controls documented complied with the standard and implementation guidance for safeguards as defined by the HIPAA Security Rule including the following:

    • Administrative Safeguards

    • Physical Safeguards

    • Technical Safeguards

    • Organizational Requirements

    • Breach Notification

  • The controls were suitably designed and implemented as of November 22, 2022, to provide reasonable assurance that the applicable HIPAA and HITECH requirements are met.

For more information please get in touch at security@piano.io.

Last updated: