PProvenIQ

HIPAA Compliance

Last Updated: March 25, 2026

Our Commitment to Patient Privacy

ProvenIQ Health takes the protection of patient health information seriously. We are designed from the ground up to support HIPAA compliance for our partner practices.

How ProvenIQ Handles Clinical Data

PHI Stays in Your System

ProvenIQ connects to your EHR via read-only API access. Protected Health Information (PHI) remains in your electronic health record system at all times. We do not store, copy, or transfer identifiable patient records to our servers.

De-Identified Data Processing

The clinical intelligence ProvenIQ generates is built from de-identified data. We follow the HIPAA Safe Harbor method for de-identification, removing all 18 categories of identifiers specified under 45 CFR 164.514(b)(2) before any data is used in our analytics pipeline.

Business Associate Agreements

For practices that require it, ProvenIQ will execute a Business Associate Agreement (BAA) prior to any data integration. This ensures all parties understand their responsibilities for protecting health information under HIPAA.

Technical Safeguards

  • Encryption: All data in transit is encrypted using TLS 1.3. Data at rest is encrypted using AES-256.
  • Access Controls: Role-based access controls ensure only authorized personnel can access clinical analytics.
  • Audit Logging: All access to clinical data and system actions are logged and auditable.
  • Infrastructure: Our platform is hosted on SOC 2 Type II compliant infrastructure with regular security assessments.

Administrative Safeguards

  • Designated privacy and security officers
  • Regular workforce training on HIPAA requirements
  • Documented policies and procedures for data handling
  • Incident response and breach notification procedures
  • Regular risk assessments and security reviews

Your Practice's Responsibilities

As the covered entity, your practice maintains responsibility for obtaining appropriate patient consent, managing access to ProvenIQ within your organization, and reporting any suspected security incidents.

Questions

For questions about our HIPAA compliance practices or to request a BAA, contact us at compliance@proveniq.health.