Security requirements for HIPAA-enabled accounts

Plan requirement

Subscription Any plan
Access Admin

Accounts handling health information carry conditions. They are requirements, not suggestions, and using a feature outside them breaks the arrangement.

The shape of the conditions

  • Authentication. Stricter sign-in requirements for everyone with access.
  • Access control. Agents see only what their work requires.
  • Feature restrictions. Some capabilities may not be used on such an account.
  • Retention and deletion, configured deliberately rather than left open.
  • Auditability. Being able to show who did what.

The specific list for your account comes from your agreement, not from a general description.

Feature restrictions catch people out

Adding an integration, an app or a new channel can take an account outside the conditions without anybody intending it. The change looks routine and the consequence is not.

Any addition to such an account should be checked before it is made, not after.

Access control is the practical work

Roles that limit what each agent can open. This is where accounts most often fall short, because broad access is convenient and the restriction has to be designed.

Train the people, not just the platform

Agents need to know what they may put in a ticket, what they may export, and what they must never paste elsewhere. That is where the real exposure sits, and no setting covers it.

Write down the configuration

What is configured, why, and when it was last checked. That document is what you produce when somebody asks, and reconstructing it later is far harder.

Check before changing anything

Contact pluscloud support before adding features or integrations to an account under these conditions, and we will confirm whether it is within scope.

See also

Was this article helpful?

0

Still stuck?

Our support team will take a look with you.

Comments

0 comments

Article is closed for comments.