Plan requirement
| Subscription | Any plan |
| Access | Admin |
The question does not have a yes or no answer. Compliance depends on an agreement and on how you configure and use the account.
Why software cannot be compliant by itself
HIPAA places obligations on organisations, not on products. A tool can support those obligations or make them harder to meet; it cannot discharge them for you.
Any supplier claiming their product simply is compliant is describing something that does not exist.
What is actually required
- An agreement in place covering the handling of protected health information.
- The account configured to the conditions that agreement requires.
- Your own working practices aligned: access, retention, what agents may do.
All three. Any one on its own is not enough.
Configuration is not optional
An account operating under such an agreement has conditions attached: how it is secured, which features may be used, how data is handled. Those are requirements rather than recommendations, and using a feature outside them undoes the arrangement.
The part people underestimate
Working practices. Who can open which tickets, what leaves in an export, what agents paste into other systems. Configuration is checkable; habits are what actually go wrong.
This is not legal advice
What you must do is determined by your obligations and your counsel, not by documentation. This article describes what is involved, not whether your arrangement is sufficient.
What to do next
Contact pluscloud support before handling health information in Zendesk. We will go through what needs to be in place for your account and what it means for how you work.
Comments
0 comments
Article is closed for comments.