Map the information

Identify what information the service receives, where it is processed, which channels are involved, and who can access it. Keep the marketing website separate from patient workflows.

Review agreements and documentation

For workflows involving protected health information, review the applicable Business Associate Agreement with your compliance team. Request security reports and read their scope and covered period.

Ask operational questions

Discuss access permissions, audit records, retention and deletion, service providers, incident response, and how changes to the deployment are reviewed. Ask for evidence relevant to your intended setup.

Test boundaries before launch

Verify the administrative tasks, clinical handoff, identity checks where needed, and permitted information for each channel. This is a procurement planning guide, not a legal determination of compliance. See HHS guidance on business associates for the underlying framework.

HHS: business associate guidance ↗Book a demoTalk to our AI