Privacy and compliance
Learn more about how we meet HIPAA, PHIPA, PIPEDA & GDPR regulations while providing you with our service and support to enhance your healthcare and well-being practice.
Learn more about how we meet HIPAA, PHIPA, PIPEDA & GDPR regulations while providing you with our service and support to enhance your healthcare and well-being practice.
Yes. The Upheal platform empowers healing professionals to concentrate on their services by offering automated notes and analytics for client conversations. As a part of this process, Upheal handles protected health information for practitioners, adhering to HIPAA regulations as a Business Associate.
Upheal fully complies with the HIPAA Security Rule and Privacy Rule, ensuring that clients’ electronic health information (ePHI) is protected with proper administrative, physical, and technical safeguards to ensure confidentiality, integrity, and security.
Our platform provides a secure environment for your ePHI through a combination of technical and nontechnical measures. Learn more here.
Yes. We have undergone an assessment by a 3rd party auditor which confirmed we are meeting all requirements set by the Personal Health Information Protection Act (PHIPA) and the Personal Information Protection and Electronic Document Act (PIPEDA).
This means that whether you're using our product across Canada or in the province of Ontario, your data remains under the safeguard of the highest privacy protocols.
Yes. Upheal is fully compliant with the General Data Protection Regulation (GDPR), UK GDPR, and UK Data Protection Act (DPA). We prioritize the privacy and protection of our users' personal data, ensuring that all data processing activities are carried out in accordance with the stringent requirements set forth by these regulations.
Yes. You can find our Business Associate Agreement (BAA) here which governs our cooperation between us as a Business Associate and healing professionals when they are defined as a Covered Entity under HIPAA. All Covered Entities who use our platform agree to the terms of the BAA upon signing up.
Personal data including protected health information (PHI) processed by the Upheal platform is stored in a pseudonymized format. This means that personal data is not stored in its original form but is instead replaced with a pseudonym or a random identifier. This process ensures that personal data is not directly identifiable, reducing the risk of unauthorized access to sensitive information.
Upheal only accesses a client’s protected health information (PHI) when it’s necessary in investigating a technical issue that a care provider reports to Upheal Support. Most technical problems are solved without any access to PHI, but sometimes, we need to see some details to understand exactly what went wrong. The Upheal Support team who may access PHI are HIPAA-trained engineers and act in line with our SOC 2 Type II attestation. They do not share, sell, or expose your data to others.
Access to personal data is strictly controlled and limited to individuals who require access to perform their job functions. All access to personal data is logged and monitored, and access rights are reviewed regularly to ensure that they are appropriate and up-to-date.
At Upheal, we are committed to protecting the data on our platform and have therefore implemented several measures to ensure its security. We understand that trust is critical in our industry, and we are therefore committed to protecting our customers' data:
Upheal reviews the platform’s security regularly to ensure that it remains effective and up-to-date.
We've put together some best practices to help protect sensitive information while using our platform:
Don’t forget to also follow any security guidelines that may apply to you as a professional in your location. By following these best practices, you can help ensure the security and confidentiality of data while using Upheal. We are committed to maintaining the highest standards of data protection, and we encourage our community to do the same.
Yes, we offer various methods to collect client consent through the app. It can be shared via email or directly during the call. For more details about the consent collection process, you can visit the support center. Additionally, you can check this Privacy Policy template.