HIPAA Compliance
Your privacy and security are our top priorities. Learn how we protect your health information.
Fully HIPAA Compliant Platform
Sych is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA) and implements comprehensive safeguards to protect your Protected Health Information (PHI).
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that requires the protection and confidential handling of protected health information (PHI). HIPAA establishes national standards for:
- Privacy Rule: Governs the use and disclosure of PHI
- Security Rule: Sets standards for electronic PHI (ePHI) security
- Breach Notification Rule: Requires notification of PHI breaches
- Enforcement Rule: Establishes penalties for HIPAA violations
As a healthcare technology platform, Sych is required to comply with all applicable HIPAA regulations and ensure that your health information is protected at all times.
Our Commitment to HIPAA Compliance
At Sych, HIPAA compliance is not just a legal requirement—it's a fundamental aspect of how we build and operate our platform. We are committed to:
Protecting Your Privacy
We implement strict access controls and only use your PHI for treatment, payment, and healthcare operations.
Securing Your Data
We use industry-leading encryption and security measures to protect your information from unauthorized access.
Maintaining Compliance
We conduct regular audits, risk assessments, and staff training to ensure ongoing HIPAA compliance.
Empowering Your Rights
We respect your rights to access, amend, and control your health information.
Comprehensive Security Safeguards
HIPAA requires covered entities to implement administrative, physical, and technical safeguards. Here's how Sych meets these requirements:
Administrative Safeguards
Regular risk assessments, security incident procedures, and continuous monitoring
Comprehensive HIPAA training for all employees with annual refresher courses
Role-based access controls ensuring employees only access PHI necessary for their job functions
Dedicated privacy and security officers responsible for HIPAA compliance oversight
Physical Safeguards
SOC 2 Type II certified facilities with 24/7 security monitoring and access controls
Automatic screen locks, encrypted hard drives, and secure disposal of physical media
Policies governing the use of mobile devices and removal of hardware
Technical Safeguards
256-bit SSL/TLS encryption for data in transit and AES-256 encryption for data at rest
Multi-factor authentication, unique user identification, and automatic logoff
Comprehensive logging of all access to ePHI with regular review and analysis
Mechanisms to ensure ePHI is not improperly altered or destroyed
End-to-end encryption for all video sessions and secure messaging
How We Handle Your Protected Health Information
Permitted Uses and Disclosures
We use and disclose your PHI only for:
- Treatment: Facilitating care from your healthcare provider
- Payment: Processing billing and insurance claims
- Healthcare Operations: Quality improvement, training, and business management
- Your Authorization: Other uses only with your written consent
- Legal Requirements: When required by law or court order
Minimum Necessary Standard
We follow the "minimum necessary" standard, using and disclosing only the minimum amount of PHI required to accomplish the intended purpose.
Data Retention
We retain your health information in accordance with federal and state law requirements, typically for a minimum of 6 years after your last activity. You may request deletion of your data subject to legal retention requirements.
Business Associate Agreements
We work with carefully vetted third-party service providers who may have access to your PHI. HIPAA requires us to have Business Associate Agreements (BAAs) with these providers, ensuring they:
- Implement appropriate safeguards to protect PHI
- Use and disclose PHI only as permitted
- Report any security incidents or breaches
- Ensure their subcontractors comply with HIPAA
- Return or destroy PHI when services end
Our business associates include:
- Cloud hosting providers (AWS, Google Cloud Platform)
- Payment processors (Stripe, Square)
- Analytics services (with de-identified data only)
- Email and communication services
Your HIPAA Rights
Under HIPAA, you have the following rights regarding your health information:
Right to Access
You may view and obtain copies of your health records. You can download your records from your account dashboard at any time.
Right to Amend
You may request corrections to your health information if you believe it is inaccurate or incomplete.
Right to an Accounting
You may request a list of certain disclosures of your health information.
Right to Request Restrictions
You may request limitations on how we use or disclose your PHI.
Right to Confidential Communications
You may request communications by alternative means or at alternative locations.
Right to a Paper Copy
You may request a paper copy of our Notice of Privacy Practices at any time.
To exercise any of these rights, please contact our Privacy Officer at sychhealthapp@gmail.com or through your account settings.
Breach Notification Procedures
In the unlikely event of a breach of your unsecured PHI, we will:
Immediate Response
- Investigate the incident within 24 hours
- Take immediate steps to mitigate harm
- Document the breach and remedial actions
- Report to appropriate authorities
Notification
If a breach affects you, we will notify you:
- When: Within 60 days of discovering the breach
- How: By email, mail, or phone
- What: Description of the breach, types of information involved, steps we're taking, and what you can do to protect yourself
Regulatory Notification
We will also notify the Department of Health and Human Services and, if the breach affects more than 500 individuals, prominent media outlets.
Ongoing Compliance Efforts
HIPAA compliance is an ongoing commitment. We maintain our compliance through:
Regular Assessments
- Annual HIPAA risk assessments
- Quarterly security audits
- Penetration testing and vulnerability scans
- Third-party security certifications (SOC 2, ISO 27001)
Continuous Improvement
- Monitoring regulatory updates and guidance
- Updating policies and procedures
- Implementing new security technologies
- Responding to emerging threats
Staff Training
- HIPAA training for all new employees
- Annual refresher courses
- Role-specific training programs
- Security awareness campaigns
Questions About Our HIPAA Compliance?
If you have questions about our HIPAA compliance practices or wish to file a complaint, please contact:
Privacy Officer
Email: sychhealthapp@gmail.com
Phone: 1-800-SYCH-HELP
Address: Sych Privacy Office, 123 Healthcare Blvd, New York, NY 10001
File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with us or with:
U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: www.hhs.gov/ocr/privacy
No Retaliation: You will not be penalized or retaliated against in any way for filing a complaint.