HIPAA · Compliance

Health data handled with real safeguards, not just a promise.

How Mojo Helpdesk supports compliance with the Health Insurance Portability and Accountability Act, so teams handling protected health information can run support without putting patient privacy at risk.

Business Associate Agreement on requestSigned for eligible products that process PHI. Contact us to start.
Safeguards
Administrative, technical & physical

The three safeguard classes named in the HIPAA Security Rule.

Agreement
BAA on request

Signed for eligible products that process PHI.

Standard
45 CFR 164.306–314

The Security Rule sections we hold ourselves to.

An honest note

There is no official HIPAA “certification.”

No government body hands out a HIPAA certificate. What matters is whether an organization actually follows the Security Rule and stands behind it. Metadot performs a documented self-evaluation, holds every business associate to the same standard, and signs a Business Associate Agreement for eligible services.

A “certified” badgeNot recognized

“We paid for a HIPAA certificate.”

HHS does not recognize private HIPAA certifications. A logo is not accountability.

Metadot · MojoWhat we actually do

“We self-evaluate against the Rule, and sign a BAA.”

Documented safeguards, business associates held to the same bar, and a signed agreement. Not a sticker.

Our HIPAA commitment

Four ways we safeguard PHI.

The safeguards that keep protected health information protected, and the standard behind each one.

01

How medical data is protected

Sensitive health information is safeguarded with the same encryption and security controls behind our SOC 2 Type II attestation, in transit and at rest.

STANDARD  ·  Encryption in transit & at rest

02

Who can access it

Strict boundaries on who can view or use health information, enforced with authentication and role-based permissions rather than trust.

STANDARD  ·  MFA & role-based access

03

The standard we follow

We hold ourselves to the administrative, technical, and physical safeguards set out in 45 CFR 164.306, 308, 310, 312, and 314.

STANDARD  ·  HIPAA Security Rule

04

Who else is held to it

Every vendor that could touch protected health information is held to the same HIPAA standards we hold ourselves to.

STANDARD  ·  Business associate flow-down

Business Associate Agreement

A BAA when your compliance needs one.

Metadot Corporation provides a Business Associate Agreement (BAA) upon request for eligible products and services that support the processing of protected health information (PHI). We work with customers to help meet their HIPAA compliance requirements while maintaining appropriate administrative, technical, and physical safeguards for PHI.

To request a copy of our standard BAA or to discuss HIPAA requirements, please contact us.

Frequently asked questions

Run support that respects patient privacy.

Get a HIPAA-ready ticket system production-ready in seconds, with a BAA when you need one.