HIPAA and HopeConnect
If your organization is a covered entity, you need to know what role a vendor plays and what they do with protected health information. Here is our answer, including the parts that are still in progress.
The role we occupy
Covered entities, hospitals, clinics, health plans, and providers, use HopeConnect to coordinate referrals. In doing so we handle protected health information on their behalf, which places us in the business associate role rather than the covered entity role. We are not a healthcare provider, we do not deliver care, and we do not bill for services.
What PHI we hold, and what we do not
The most useful thing we can tell a privacy officer is how narrow the data set is. HopeConnect holds:
- The referral itself and the events in its lifecycle
- Documents attached to a referral, governed by consent
- Messages exchanged about the referral
- Appointments scheduled from the referral
- Eligibility checks for the referred service
It deliberately does not hold a patient chart, progress or therapy notes, medication lists, diagnosis history, treatment plans, or billing and claims records. This is enforced by the data model, not only by policy. There is no table for a chart because coordinating a referral does not require one.
Safeguards in the product
- Named individual user accounts rather than shared logins, so activity is attributable to a person
- Role-based access, scoped by organization and by case
- Consent gates that block a send where 42 CFR Part 2 applies
- Audit logging on writes, retained as part of the referral history
- Referral-scoped documents rather than a browsable shared repository
- Minimum necessary applied by design, through the narrow data model above
Business associate agreements
Confirm this section with counsel before publishing
A covered entity will require an executed business associate agreement before any protected health information is shared, and the specific terms, including breach notification timelines, subcontractor flow-down, and termination and data return obligations, need to reflect the agreement your legal counsel actually approves. We have not filled that in with invented terms. Replace this box with your counsel-approved statement of your BAA process, or state plainly that BAAs are executed as part of pilot onboarding on terms agreed with each organization.
Where we are
HopeConnect is pre-launch. We hold no HIPAA certification, because no such certification exists in any official form, and we display no third-party security badges we have not earned. If your privacy or security review needs specifics, ask, and we will tell you what exists today, what is in progress, and what is not built yet. Founding organizations are shaping that review process with us rather than receiving a finished packet.
Contact info@hopeconnecthealth.com for security and compliance questions.