Doseform – Compliance

Doseform Compliance

Innovation in healthcare requires trust. Assuring the privacy and security of patient data is at the core of our mission. Doseform is fully compliant with the HIPAA/HITECH regulations, as updated by the Omnibus Rule, and is also fully PCI Compliant.

HIPAA/HITECH

Doseform has instituted safeguards, policies, and procedures to protect patients’ health information, in compliance with the final rule issued by the United States Department of Health and Human Services regarding the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH). These steps include:

  • Ongoing assessments of risks to the confidentiality, integrity, and availability of patient data.
  • Implementation of policies and procedures that dictate acceptable work practices and map directly to the HIPAA Security Rule’s Administrative, Physical, and Technical Safeguards.
  • Implementation of procedural and technical safeguards to prevent Doseform employees from improperly accessing PHI.
  • Designation of a Chief Security Officer responsible for information system monitoring and information security policy oversight.
  • Mandatory HIPAA privacy and security training for all workforce members.
  • Encryption of patient data at rest and in transit according to industry-best security standards.
  • Implementation of audit trail and record retention capabilities.
  • Execution of Business Associate Agreements with customers, vendors, and subcontractors, where appropriate.
  • Regular reassessment of all policies and procedures to ensure that HIPAA/HITECH rules continue to be addressed.

Continuous Assurance

We approach compliance and security as a continuous cycle. Our technology is backed by robust monitoring tools and first responder engineer support. We’re continually improving the resilience of our system to ensure a swift incident response. We use operational feedback to continuously refine and improve our risk posture. All of our operational security metrics are monitored continuously and our compliance status is available in real-time, 24/7.