How HIPAA LINK protects your information
Encryption, who can see your clients, two-factor sign-in, and the agreements behind it.
HIPAA LINK only keeps client information when you use a feature that needs it, only for as long as it needs it, and always under our Business Associate Agreement.
This article covers the protections around that. For the list of what is kept and for how long, see What HIPAA LINK keeps, and for how long.
Sessions are encrypted
Every session is encrypted. Sessions connect peer-to-peer between you and your client whenever the network allows. When a network blocks a direct connection, or when group calling is on, sessions route through secure servers and stay encrypted the whole way.
Stored information is encrypted at rest by our cloud hosting provider.
Only your clinic sees your clients
Your client queue, your rooms and your call history belong to your clinic. Staff see only the clinic they were invited to.
You can be invited to more than one clinic with the same email address, but you are signed in to one clinic at a time. What you can see is always the clinic you are currently signed in to.
Two-factor sign-in is available
Two-factor authentication adds a code to your sign-in, so a stolen password is not enough on its own. It is available to every account and is off until you turn it on.
To turn it on, see Two-factor authentication.
Our support team
Our support team can access your account only to help you, and every action they take is logged.
The services behind HIPAA LINK
Running the product means other services handle some of the work: cloud hosting and storage, real-time communications, transcription and AI, fax delivery, payment processing, and email delivery.
Every service that handles client information on our behalf does so under a BAA.
What is yours and what is ours
Your practice is the covered entity. HIPAA LINK is a business associate, which is why we sign a Business Associate Agreement with you. See Your BAA.
That split matters in practice. We are responsible for the product: how sessions are encrypted, who can reach your clinic’s information, and what we keep. You are responsible for how your practice uses it, which includes who you give a seat to, whether you turn on two-factor, where you save the records you download, and who can see your screen while you are in a session.
HIPAA LINK is also not your record system. The clinical record stays wherever your practice keeps it.