HIPAA & data handling
Public marketing forms and client data workflows should be treated differently.
Effective Date: December 2025
BrandKlout, Inc. ("BrandKlout") is committed to maintaining the privacy and security of protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations.
1. HIPAA Compliance Commitment
As a business associate to healthcare providers, BrandKlout understands the critical importance of protecting patient information and maintaining HIPAA compliance. We have implemented comprehensive administrative, physical, and technical safeguards to protect PHI.
2. Business Associate Agreement
BrandKlout enters into Business Associate Agreements (BAAs) with covered entities as required by HIPAA. These agreements outline our responsibilities regarding the use and disclosure of PHI and ensure that we maintain appropriate safeguards.
3. Our HIPAA Safeguards
Administrative Safeguards:
- Designated Privacy and Security Officers
- Regular HIPAA training for all staff members
- Access controls and authorization procedures
- Incident response and breach notification procedures
- Regular risk assessments and audits
Technical Safeguards:
- Encryption of data in transit and at rest
- Secure authentication and access controls
- Audit controls and activity monitoring
- Automatic logoff procedures
- Data backup and disaster recovery systems
Physical Safeguards:
- Secure facility access controls
- Workstation and device security policies
- Secure disposal of PHI-containing materials
- Environmental controls and monitoring
4. Permitted Uses and Disclosures
BrandKlout uses and discloses PHI only as permitted or required by our Business Associate Agreements and HIPAA regulations. We do not use or disclose PHI for purposes other than those specified in our agreements with covered entities.
5. Patient Rights
While BrandKlout is a business associate and not a covered entity, we support our healthcare clients in upholding patient rights under HIPAA, including:
- Right to access their health information
- Right to request amendments to their health information
- Right to receive an accounting of disclosures
- Right to request restrictions on uses and disclosures
- Right to request confidential communications
6. Breach Notification
In the event of a breach of unsecured PHI, BrandKlout will notify the affected covered entity without unreasonable delay and no later than 60 days from discovery of the breach, in accordance with HIPAA breach notification requirements.
7. Subcontractors
Any subcontractors or agents that receive PHI from BrandKlout are required to enter into written agreements that impose the same restrictions and conditions on the use and disclosure of PHI that apply to BrandKlout.
8. Questions and Concerns
If you have questions about our HIPAA compliance practices or wish to report a concern, please contact:
HIPAA Privacy Officer
BrandKlout, Inc.
555 Anton Blvd
Costa Mesa, CA 92626
Email: [email protected]
Phone: (555) 123-4567
Find out if
BrandKlout can
own your market
with you.
Tell us where you are, what treatments you want to grow, and what is currently holding you back. If the market is a fit and still available, we’ll show you the biggest opportunities first.