Understanding and Enabling HIPAA Compliance in Your CRM
About HIPAA Compliance
The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is a U.S. law that sets standards for protecting sensitive patient health information. For businesses in the healthcare sector, using a CRM that handles this data requires adherence to HIPAA's privacy and security rules, specifically under Title II.
To support this, the CRM offers an optional, account-wide HIPAA Compliance Package. This is a paid upgrade; standard accounts are not HIPAA compliant. The package provides encryption for electronic Protected Health Information (ePHI), enforces Multi-Factor Authentication (MFA), includes detailed audit logging, and provides a Business Associate Agreement (BAA).
Key Features of the Package
- Account-Wide Application: Once purchased and activated, HIPAA safeguards apply to your entire agency and all its location sub-accounts.
- Included Business Associate Agreement (BAA): A signed BAA is provided as part of the subscription.
- Permanent Activation: The package is a non-refundable, non-cancelable upgrade that cannot be disabled or downgraded after purchase.
- Automatic Enforcement: Compliance features, including data encryption, are enabled automatically upon activation.
How to Subscribe to the HIPAA Compliance Package
The package is available for an additional monthly fee. Follow these steps to subscribe:
- In your main agency account, navigate to Settings.
- Select Compliance from the menu.
- Carefully review all the information presented in the Before You Buy section.
- Click the button labeled Buy HIPAA Package at $297 per Month.
- A modal window will appear. Read the note, list of features, and the acknowledgment text thoroughly.
- To proceed, check the box in the Acknowledgement section and then click Pay $297 & Subscribe.
- You will be prompted to add or select a payment method to complete the transaction.
After Purchase and BAA Signing
Once your payment is processed, you will be directed to your Documents & Contracts area to review and sign the Business Associate Agreement. The HIPAA Compliance Package is activated agency-wide immediately after the BAA is signed.
Important Final Step: The agency owner must then manually enable HIPAA compliance for each individual location sub-account. This is done within the Advanced Settings for each location to complete the security hardening process.
Managing Your Business Associate Agreement
You can view, download, and update signer details for your BAA at any time within the CRM's Documents & Contracts section. No support ticket is required to edit this information.
Security and Data Encryption
With the HIPAA package active, the CRM's database automatically encrypts all data before it is written to disk. This process requires no configuration on your part. Authorized users transparently access decrypted data. Encryption uses the 256-bit Advanced Encryption Standard (AES-256), and cryptographic keys are managed with strict access controls and regular rotation.