HIPAA Compliance
Our obligations as aBusiness Associate.
CareMax handles protected health information on behalf of covered entities. This page summarises the safeguards, controls and commitments that govern how we do it.
01Business Associate status
Under HIPAA, CareMax operates as a Business Associate when performing billing, coding, revenue cycle, technology or advisory services that involve protected health information on behalf of a covered entity.
A Business Associate Agreement is executed before any PHI is accessed. That agreement defines permitted uses and disclosures, safeguard obligations, subcontractor requirements, breach notification duties and the handling of PHI at termination.
02Administrative safeguards
We maintain documented security policies and procedures, an assigned security responsibility, and a workforce security programme covering authorization, clearance and termination procedures.
Security awareness training is delivered to all workforce members with access to PHI, with periodic refreshers and role-specific content for privileged users.
Periodic HIPAA Security Risk Assessments are conducted, findings are tracked to closure through a documented risk register, and results are reported to leadership.
03Technical safeguards
PHI is encrypted in transit and at rest using 256-bit encryption. Access is controlled on a least-privilege basis with unique user identification and enforced multi-factor authentication.
Audit controls record access to systems containing PHI. Logs are retained and reviewed, and anomalous access is investigated under our incident response procedure.
Automatic session termination, integrity controls and documented transmission security requirements apply to all systems in scope.
04Physical safeguards
Facility access is controlled and logged. Workstations handling PHI are configured to organizational standards, and device and media controls govern the receipt, movement, reuse and disposal of hardware.
Media containing PHI is sanitised or destroyed under a documented procedure before disposal or reuse, with certificates retained where applicable.
05Vendors and subcontractors
Any subcontractor that may access PHI is subject to a written agreement imposing the same restrictions and conditions that apply to CareMax.
Third-party and vendor security assessments are performed as part of our vCISO practice, covering both our own supply chain and, where engaged, our clients’.
06Incident response and breach notification
A documented incident response plan defines detection, triage, containment, eradication, recovery and post-incident review, alongside a business continuity plan that is exercised periodically.
In the event of a breach of unsecured PHI, CareMax notifies the affected covered entity without unreasonable delay and within the timeframe required by the applicable Business Associate Agreement and the HIPAA Breach Notification Rule, providing the information needed for the covered entity to meet its own notification obligations.
07Framework alignment
Our security program is aligned to the HIPAA Security Rule, the NIST Cybersecurity Framework and CIS Critical Controls, with HITECH obligations reflected in our breach and enforcement procedures.
Clients engaging our vCISO service receive executive and board-level reporting on control maturity, open risks and remediation progress against these frameworks.
Questions about this policy?
Contact us at info@caremaxbilling.com or call +1 (951) 717-8925. Written correspondence may be sent to 1301 N Broadway STE 32050, Los Angeles, CA 90012, USA.
Free revenue audit
Find out what your practice is leaving on the table.
A free revenue audit takes 30 minutes and shows you exactly where claims are being denied, underpaid or never followed up on. No obligation, no setup fee, no sales theatre.
- No setup fees
- HIPAA-compliant intake
- Reply within 1 business day