Privacy & HIPAA
Member health information is kept in strict confidence and used only as needed to perform transportation. We comply with HIPAA, including its Privacy, Security and Breach Notification rules, and we sign a business-associate agreement covering the handling of protected health information.
- Administrative, physical and technical safeguards around PHI
- Only the minimum necessary information is requested or disclosed
- Any security incident or impermissible use or disclosure is reported within three business days
- A breach of unsecured PHI is notified without unreasonable delay, and no later than 24 hours after discovery
- PHI is returned or destroyed — with documentation — when the relationship ends