|
|
|
|
MammoBase is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA). HIPAA, as you know, is deeply concerned about the protection of the confidentiality of patient information as it is passed to other entities. Since MammoBase does not perform billing, it is not passing any patient information whatsoever to insurance companies or other payors. Indeed, it does not make patient information accessible to other workstations even inside the hospital or clinic unless those workstations have the application installed and are actively running MammoBase. Thus, only workstations and personnel which are actively involved in managing the breast care of patients have access to MammoBase data. For those workstations that DO run MammoBase, access to the application is password controlled. And even within the application, functional security is implemented through a further set of passwords...to limit access to the various areas of the program on a "need to use" basis. From time to time, for troubleshooting purposes, you may wish for our tech support people to view some of your patient data. Since in this case, we in the MammoBase company are acting "for or on behalf of" your facility, we are considered by the Act to be "business associates" of your facility. HIPAA expressly allows business associates to view protected information in the course of providing services to your facility.
|
|
|