Compliance

HIPAA Compliance

Effective June 23, 2026

Better Ops Consulting(“we,” “us,” “our”) takes the privacy and security of protected health information (“PHI”) seriously. When we handle PHI on behalf of a client, we act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) and comply with the applicable requirements of the HIPAA Privacy, Security, and Breach Notification Rules. This page summarizes our commitments and the safeguards we maintain.

§ 01

Our Role Under HIPAA

Better Ops is generally a Business Associate, not a Covered Entity. When a covered entity (such as a healthcare provider or health plan) or another business associate engages us to perform services that involve access to PHI, we do so under a written Business Associate Agreement.

We sign a Business Associate Agreement (BAA) before any PHI is shared with us, and we use and disclose PHI only as permitted by that agreement, by the individual who is the subject of the PHI, or as required by law.
§ 02

Information We May Handle

Depending on the engagement, the PHI we process on a client’s behalf may include:

  • Identifiers such as name, address, dates, phone number, email address, and medical record or account numbers.
  • Treatment, intake, scheduling, and billing information contained in the records a client asks us to process or integrate.
  • Communications and documents that a client routes through the systems we help operate.

Minimum necessary. We access, use, and disclose only the minimum amount of PHI reasonably necessary to perform the contracted services.

§ 03

Administrative Safeguards

  • A designated individual responsible for our privacy and security program.
  • Written policies and procedures governing the handling of PHI.
  • Periodic risk assessments and remediation of identified gaps.
  • Role-based access, granted on a need-to-know basis and revoked promptly when no longer required.
  • A documented incident response and breach notification process.
§ 04

Physical Safeguards

  • Controlled access to facilities, workstations, and devices used to process PHI.
  • Workstation and device policies that protect against unauthorized viewing or access.
  • Secure destruction or return of media containing PHI when it is no longer needed.
§ 05

Technical Safeguards

  • Encryption of PHI in transit (TLS) and at rest using industry-standard methods.
  • Unique user accounts, role-based access controls, and multi-factor authentication.
  • Audit logging of access to systems that store or process PHI.
  • Automatic session timeout and routine patching of the systems we operate.
§ 06

Business Associate Agreements

We enter into a BAA with each covered entity or business associate we serve. Where a subcontractor may create, receive, maintain, or transmit PHI on our behalf, we flow down equivalent privacy and security obligations through a written agreement before any PHI is shared.

§ 07

Subcontractors & Vendors

We vet the vendors and platforms we rely on for appropriate safeguards, require BAAs where they may handle PHI, and limit their access to the minimum necessary to perform their function.

§ 08

Breach Notification

If we discover a breach of unsecured PHI, we investigate and mitigate the incident, and we notify the affected covered entity without unreasonable delay, consistent with the HIPAA Breach Notification Rule and the terms of the applicable BAA. The covered entity remains responsible for any required notifications to individuals, regulators, or the public.

§ 09

Workforce Training

Members of our team who may handle PHI receive HIPAA awareness training appropriate to their role. We maintain a sanctions policy for violations of our privacy and security policies.

§ 10

Data Retention & Disposal

We retain PHI only as long as necessary to provide the contracted services or as required by the applicable BAA and law. When PHI is no longer needed, we securely destroy it or return it to the client in accordance with our agreement.

§ 11

Requesting a BAA & Individual Rights

Covered entities and prospective clients may request a Business Associate Agreement before engaging us. Individuals seeking to access, amend, or otherwise exercise rights over their PHI should contact the covered entity that maintains their records. We support our clients in responding to such requests as required by HIPAA and the applicable BAA.

This page is a summary of our practices and is not legal advice. The signed Business Associate Agreement governs the specific terms of any engagement involving PHI.

§ 12

Contact Us

For questions about our HIPAA practices or to request a Business Associate Agreement, reach us directly at:

Phone:
Better Ops Consulting· Las Vegas, NV · United States