HIPAA · Compliance

Health data handled with real safeguards, not just a promise.

How Mojo Helpdesk supports compliance with the Health Insurance Portability and Accountability Act, so teams handling protected health information can run support without putting patient privacy at risk.

Business Associate Agreement availableFor customers on our Enterprise Plan, our standard Business Associate Agreement (BAA) is available to support the processing of Protected Health Information (PHI). Contact us to request a BAA.
Safeguards
Administrative, physical & technical

Safeguards designed to protect the confidentiality, integrity, and availability of PHI.

Agreement
BAA available

Available for eligible Enterprise Plan subscriptions that support the processing of PHI.

Standard
HIPAA Security Rule

Applicable requirements of 45 C.F.R. Part 164, Subpart C.

There is no official HIPAA “certification.”

Metadot maintains administrative, physical, and technical safeguards designed to protect PHI and comply with applicable HIPAA requirements. Subcontractors that create, receive, maintain, or transmit PHI on Metadot’s behalf are required to agree to applicable restrictions, conditions, and requirements concerning PHI. Metadot provides its standard Business Associate Agreement (BAA) for customers on our Enterprise Plan.

A “certified” badgeNot recognized

“We paid for a HIPAA certificate.”

HHS does not recognize private HIPAA certifications. A logo is not accountability.

“We maintain safeguards designed to protect PHI and provide our standard BAA for customers on our Enterprise Plan.”

Documented safeguards, appropriate requirements for subcontractors handling PHI, and a Business Associate Agreement for customers on our Enterprise Plan.

Our HIPAA commitment

Four ways we safeguard PHI.

The safeguards that keep protected health information protected, and the standard behind each one.

01

How medical data is protected

Protected Health Information (PHI) is protected using administrative, physical, and technical safeguards, including encryption in transit and at rest.

STANDARD  ·  Encryption in transit & at rest

02

Who can access it

Access to Protected Health Information (PHI) is restricted through authentication, access controls, and role-based permissions.

STANDARD  ·  MFA & role-based access

03

The standard we follow

Metadot maintains reasonable and appropriate administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI) and complies with applicable requirements of the HIPAA Security Rule.

STANDARD  ·  HIPAA Security Rule

04

Who else is held to it

Subcontractors that create, receive, maintain, or transmit Protected Health Information (PHI) on Metadot’s behalf are required to agree to applicable restrictions, conditions, and requirements concerning PHI as required by the HIPAA Rules.

STANDARD  ·  Subcontractor requirements

Business Associate Agreement

A BAA when your compliance needs one.

For customers on our Enterprise Plan, Metadot Corporation provides its standard Business Associate Agreement (BAA) to support the processing of Protected Health Information (PHI) through Mojo Helpdesk. The BAA describes Metadot’s obligations for the use, disclosure, safeguarding, and handling of PHI in connection with the covered Services.

To request our standard BAA or discuss HIPAA requirements for your Enterprise Plan, please contact us.

Frequently asked questions

Run support that respects patient privacy.

Use Mojo Helpdesk to support workflows involving Protected Health Information (PHI), with our standard Business Associate Agreement (BAA) available for customers on our Enterprise Plan.