HIPAA compliance might not be an exciting topic for everybody — however for our prospects who want it? They really want it.
Whenever you’re dealing with delicate information like Protected Well being Info (PHI), that you must make sure the instruments you employ adhere to the identical excessive privateness and safety requirements you do.
For organizations that require HIPAA-compliant buyer messaging, there’s an extra layer of complexity relating to evaluating instruments. We all know it’s not straightforward, so we’ve made issues as easy and as clear as we will.
This can be a chapter in our Final Information to Setting Up a Assist Desk System. Whenever you’re prepared, try the opposite chapters:
What’s HIPAA?
HIPAA stands for the U.S. Well being Insurance coverage Portability and Accountability Act of 1996 which, amongst different rights and protections, requires the confidential dealing with of PHI, or Protected Well being Info. (Digital Protected Well being Info is commonly abbreviated ePHI.)
The act’s main goals are twofold: to empower people with enhanced entry to their medical data and higher autonomy over how their personally identifiable well being information is utilized and shared, and to determine a nationwide normal for the safety of delicate affected person well being data.
HIPAA privateness laws mandate that healthcare suppliers, organizations, and their enterprise associates adhere to rigorous procedures to make sure the confidentiality and safety of PHI throughout its switch, reception, dealing with, or sharing. These measures purpose to protect the privateness and integrity of people’ well being information, fostering belief and accountability inside the healthcare system.
Not all service desk options are created equal
There aren’t many HIPAA-compliant assist desks on the market, and the few that do exist typically lack different options assist groups must do their work (similar to strong, dependable reporting). However integrating further apps to bridge these gaps is one other can of worms, as a result of these third-party instruments additionally must be HIPAA compliant.
That’s why Assist Scout is commonly a great match for entities who wish to centralize their buyer assist in a HIPAA-compliant means — as a result of along with superior safety and privateness requirements, it’s greater than a assist or service desk.
Assist Scout is customer support software program that allows you to join along with your prospects through e-mail, reside chat, and in-app messaging. All incoming messages are routed right into a unified shared inbox, making it straightforward to your staff to work collectively to reply to affected person and consumer wants.
Our shared inbox is filled with collaborative options like dialog assignments, inside notes, collision detection, and the power to tag teammates whenever you want further assist on a request.
Assist Scout additionally has productiveness options like saved replies that can assist you reply to widespread questions extra shortly and workflows to assist automate repetitive duties. Tags and customized fields will help maintain your inbox organized and may also be used for creating customized report views and workflows.
Attempt Assist Scout free for 15 days:
Assist Scout: The HIPAA-compliant assist desk software program you possibly can belief
We assist our prospects stay HIPAA compliant over common channels like e-mail, reside chat, and in-app messaging in a lot of methods.
Enterprise affiliate agreements (BAA): Assist Scout’s enterprise affiliate agreements (BAAs) are posted on-line, and we’ll signal one upon request.
Information storage location: Assist Scout is hosted on Amazon Internet Providers (AWS), a scalable, cloud-based computing platform with end-to-end safety and built-in privateness options. AWS is HIPAA compliant, enabling lined entities topic to HIPAA to make use of their safe surroundings to course of, preserve, and retailer protected well being data. For extra detailed data, see the whitepaper Architecting for HIPAA Safety and Compliance on Amazon Internet Providers.
Uptime and information availability: We try for a 99.99% uptime throughout all of our merchandise.
Person authentication: Assist Scout helps two-factor authentication (2FA) entry for Assist Scout credentials or SSO by Google Apps. Sure plans have choices for enabling authentication through any SAML-compatible id supplier.
IP restrictions: Limiting entry to your Assist Scout account to a predefined checklist of IP addresses is obtainable with some plans.
Information safety: Assist Scout’s inside software communications (together with notes, API calls, and Beacon conversations) are encrypted over 256-bit SSL (safe sockets layer).
Content material management: By a thread choices menu, you possibly can edit, delete, or conceal thread contents. This prevents that data from being despatched out once more or from being quoted in a future reply. That is useful if there are a number of events concerned in a single dialog.
Audits: Assist Scout completes common audits and annual threat assessments to make sure continued HIPAA compliance. This consists of updating, reviewing, and testing our catastrophe restoration plan.
Worker coaching: All Assist Scout staff endure annual HIPAA coaching. Our staff by no means accesses buyer accounts until we’re explicitly requested for assist. As well as, prospects may also request that we by no means entry their account for any motive.
A word about HIPAA compliance in Assist Scout:
Assist Scout makes use of e-mail protocol to ship messages — that’s why emails that come by Assist Scout appear like common e-mail versus one thing the recipient has to signal into by a safe portal. Because it’s not a system that requires a password to open attachments, for instance, there’s no assure that delicate ePHI might be 100% safe and personal — e-mail can at all times be intercepted.
For that motive, no e-mail assist desk can ever really declare itself HIPAA compliant, as a result of e-mail is inherently insecure. Organizations can, nonetheless, use Assist Scout’s absolutely featured API to construct a portal on prime of ours when deemed needed. For a lot of smaller well being tech corporations or medical practices, that may be a compelling answer.
Exterior of e-mail, it must also be famous that Assist Scout’s AI options, information base answer (Docs), and third-party integrations should not thought-about to be HIPAA compliant.
HIPAA compliance FAQs
Nonetheless have questions on HIPAA compliance? Listed below are some solutions to a couple FAQs.
What are the important thing parts of HIPAA?
The important thing parts of HIPAA are:
Protected Well being Info (PHI): This refers to any details about well being standing, provision of well being care, or cost for well being care that may be linked to a selected particular person. That is interpreted broadly and consists of any a part of a affected person’s medical file or cost historical past.
Digital Protected Well being Info (ePHI): As digital well being data grew to become extra prevalent, the necessity to defend digital affected person data grew. Any PHI that’s produced, saved, transferred, or acquired in an digital type is roofed by ePHI.
HIPAA Privateness Rule: This rule offers federal protections for PHI held by lined entities and provides sufferers varied rights with respect to that data. It additionally permits the disclosure of PHI wanted for affected person care and different essential functions.
HIPAA Safety Rule: This rule establishes nationwide requirements to guard people’ digital private well being data that’s created, acquired, used, or maintained by a lined entity. It requires applicable administrative, bodily, and technical safeguards to make sure the confidentiality, integrity, and safety of digital protected well being data.
Assist Scout maintains ongoing compliance with the U.S. Well being Insurance coverage Portability and Accountability Act and is ready to course of, preserve, and retailer protected well being data for any entities restricted by these laws.
What’s a enterprise affiliate settlement (BAA)?
A enterprise affiliate settlement, or BAA, is a contract signed by two enterprise entities that outlines the duties of every social gathering in upholding HIPAA requirements and conserving PHI protected and confidential.
You may learn extra about them on the Well being and Human Providers (HHS) web site.
HIPAA necessities: What makes a assist desk HIPAA compliant?
Whereas not all assist desks meet the regulation’s requirements out of the field, many may be configured to be compliant with HIPAA pointers. Listed below are some issues to search for:
Sturdy information safety: Digital information should be encrypted, and any internet hosting companies utilized by your assist desk supplier should additionally present a excessive degree of bodily safety.
Dependable uptime: Sufferers should have dependable entry to their ePHI, that means that you must be certain that any supplier you select is reliable.
Information location: Information should be saved within the U.S. to be HIPAA compliant.
Entry restrictions: Communication platforms ought to supply methods to guard entry to PHI, similar to 2FA, IP restrictions, SSL certificates, and many others.
Enterprise affiliate agreements (BAA): The assistance desk you select ought to be prepared to signal a BAA along with your firm.
Remember the fact that following the rules above doesn’t in and of itself make your group or your assist desk answer HIPAA compliant. All the time seek the advice of with an knowledgeable when establishing new programs to your group.
What are some examples of HIPAA violations?
To assist illustrate what a HIPAA violation would possibly appear like relating to affected person communications, listed here are two examples:
Sharing a login: It’s widespread for small companies to handle consumer requests through a free or cheap e-mail service similar to Gmail. Some might even share login credentials amongst the staff. HIPAA requires that people solely have entry to the PHI they should do their job — on this case, serving to prospects. Sharing a login may result in unauthorized entry to PHI and, in the end, a HIPAA violation.
Unattended or misplaced units: Whereas working remotely has grown extra widespread lately, it might spell hassle for companies that should adhere to HIPAA’s required safety pointers. Misplaced or unattended work units can doubtlessly result in unauthorized entry to PHI by household, pals, or unhealthy actors.
Platforms like Assist Scout will help decrease your publicity to some of these HIPAA violations by options like particular person consumer profiles with roles and permissions, and plans that embody IP restrictions.
The place can I learn extra about Assist Scout and HIPAA compliance?
Attempt Assist Scout free for 15 days:
Maintaining the human contact: Assist Scout takes the ticket out of ticketing programs
Simply since you’re accountable to guidelines and laws doesn’t imply your e-mail assist needs to be impersonal.
You may adjust to HIPAA laws and deal with your prospects and different stakeholders just like the people they’re.
The unlucky facet impact of many assist desks is that the shopper expertise suffers. Customers encounter obstacles as an alternative of frictionless communication; each buyer who begins a dialog has the truth that their “ticket” is being processed shoved of their face.
The very best assist desk software program is the one your prospects do not even discover. There’s something a few plain textual content e-mail that’s pleasant and acquainted. We ship these emails to our pals, co-workers, and members of the family. We don’t ship them aggressively stylized, amorphous pamphlets that place design over perform.
When your prospects obtain emails from you, the truth that it seems to be like some other e-mail signifies that it doesn’t place a visible barrier between them and your organization — you get to have a private dialog with a human contact.
Sufferers need to have their private data and medical data protected, however nothing about these protections precludes well being care suppliers from treating them like people. To that finish, well being care organizations and Assist Scout share the identical aim: serving to folks.
Speak to our pleasant staff to find whether or not Assist Scout may be the correct HIPAA-compliant assist desk for you.