Skip to main content

HIPAA overview

MASLOW operates as a business associate under HIPAA. We execute Business Associate Agreements (BAAs) with all covered entity clients and maintain safeguards required under the HIPAA Security Rule.

Technical safeguards

SafeguardImplementation
Access controlRole-based access, unique user IDs, automatic session timeout
Audit controlsAll access to PHI is logged with timestamps and user identity
Integrity controlsData validation, checksums, and version tracking
Transmission securityTLS 1.2+ for all data in transit

Administrative safeguards

  • Workforce training — all MASLOW team members receive HIPAA training
  • Access management — access to production systems restricted to authorized personnel
  • Incident response — documented procedures for identifying and responding to security incidents
  • Risk assessments — regular security risk assessments conducted

Physical safeguards

MASLOW infrastructure runs on AWS, which maintains physical security controls including:
  • Data center access controls
  • Environmental protections
  • Equipment disposal procedures

Breach notification

In the event of a breach involving PHI, MASLOW follows HIPAA breach notification requirements, including timely notification to affected covered entities.

Questions

For questions about MASLOW’s HIPAA compliance, contact compliance@maslowhealth.com.