> ## Documentation Index
> Fetch the complete documentation index at: https://docs.maslow.health/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA compliance

> How MASLOW meets HIPAA requirements for handling protected health information

## HIPAA overview

MASLOW operates as a business associate under HIPAA. We execute Business Associate Agreements (BAAs) with all covered entity clients and maintain safeguards required under the HIPAA Security Rule.

## Technical safeguards

| Safeguard                 | Implementation                                                |
| ------------------------- | ------------------------------------------------------------- |
| **Access control**        | Role-based access, unique user IDs, automatic session timeout |
| **Audit controls**        | All access to PHI is logged with timestamps and user identity |
| **Integrity controls**    | Data validation, checksums, and version tracking              |
| **Transmission security** | TLS 1.2+ for all data in transit                              |

## Administrative safeguards

* **Workforce training** — all MASLOW team members receive HIPAA training
* **Access management** — access to production systems restricted to authorized personnel
* **Incident response** — documented procedures for identifying and responding to security incidents
* **Risk assessments** — regular security risk assessments conducted

## Physical safeguards

MASLOW infrastructure runs on AWS, which maintains physical security controls including:

* Data center access controls
* Environmental protections
* Equipment disposal procedures

## Breach notification

In the event of a breach involving PHI, MASLOW follows HIPAA breach notification requirements, including timely notification to affected covered entities.

## Questions

For questions about MASLOW's HIPAA compliance, contact **[compliance@maslowhealth.com](mailto:compliance@maslowhealth.com)**.
