Health data handled with real safeguards, not just a promise.
How Mojo Helpdesk supports compliance with the Health Insurance Portability and Accountability Act, so teams handling protected health information can run support without putting patient privacy at risk.
- Safeguards
- Administrative, technical & physical
- Agreement
- BAA on request
- Standard
- 45 CFR 164.306–314
The three safeguard classes named in the HIPAA Security Rule.
Signed for eligible products that process PHI.
The Security Rule sections we hold ourselves to.
There is no official HIPAA “certification.”
No government body hands out a HIPAA certificate. What matters is whether an organization actually follows the Security Rule and stands behind it. Metadot performs a documented self-evaluation, holds every business associate to the same standard, and signs a Business Associate Agreement for eligible services.
“We paid for a HIPAA certificate.”
HHS does not recognize private HIPAA certifications. A logo is not accountability.
“We self-evaluate against the Rule, and sign a BAA.”
Documented safeguards, business associates held to the same bar, and a signed agreement. Not a sticker.
Four ways we safeguard PHI.
The safeguards that keep protected health information protected, and the standard behind each one.
How medical data is protected
Sensitive health information is safeguarded with the same encryption and security controls behind our SOC 2 Type II attestation, in transit and at rest.
STANDARD · Encryption in transit & at rest
Who can access it
Strict boundaries on who can view or use health information, enforced with authentication and role-based permissions rather than trust.
STANDARD · MFA & role-based access
The standard we follow
We hold ourselves to the administrative, technical, and physical safeguards set out in 45 CFR 164.306, 308, 310, 312, and 314.
STANDARD · HIPAA Security Rule
Who else is held to it
Every vendor that could touch protected health information is held to the same HIPAA standards we hold ourselves to.
STANDARD · Business associate flow-down
A BAA when your compliance needs one.
Metadot Corporation provides a Business Associate Agreement (BAA) upon request for eligible products and services that support the processing of protected health information (PHI). We work with customers to help meet their HIPAA compliance requirements while maintaining appropriate administrative, technical, and physical safeguards for PHI.
To request a copy of our standard BAA or to discuss HIPAA requirements, please contact us.
Frequently asked questions
Run support that respects patient privacy.
Get a HIPAA-ready ticket system production-ready in seconds, with a BAA when you need one.