Providers: your first month is free — no credit card required. See pricing →
HIPAA Compliant

HIPAA Compliance

Your privacy and security are our top priorities. Learn how we protect your health information.

Fully HIPAA Compliant Platform

Sych is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA) and implements comprehensive safeguards to protect your Protected Health Information (PHI).

What is HIPAA?


The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that requires the protection and confidential handling of protected health information (PHI). HIPAA establishes national standards for:

  • Privacy Rule: Governs the use and disclosure of PHI
  • Security Rule: Sets standards for electronic PHI (ePHI) security
  • Breach Notification Rule: Requires notification of PHI breaches
  • Enforcement Rule: Establishes penalties for HIPAA violations

As a healthcare technology platform, Sych is required to comply with all applicable HIPAA regulations and ensure that your health information is protected at all times.

Our Commitment to HIPAA Compliance


At Sych, HIPAA compliance is not just a legal requirement—it's a fundamental aspect of how we build and operate our platform. We are committed to:

Protecting Your Privacy

We implement strict access controls and only use your PHI for treatment, payment, and healthcare operations.

Securing Your Data

We use industry-leading encryption and security measures to protect your information from unauthorized access.

Maintaining Compliance

We conduct regular audits, risk assessments, and staff training to ensure ongoing HIPAA compliance.

Empowering Your Rights

We respect your rights to access, amend, and control your health information.

Comprehensive Security Safeguards


HIPAA requires covered entities to implement administrative, physical, and technical safeguards. Here's how Sych meets these requirements:

Administrative Safeguards

Security Management Process

Regular risk assessments, security incident procedures, and continuous monitoring

Workforce Training

Comprehensive HIPAA training for all employees with annual refresher courses

Access Management

Role-based access controls ensuring employees only access PHI necessary for their job functions

Security Officer

Dedicated privacy and security officers responsible for HIPAA compliance oversight

Physical Safeguards

Secure Data Centers

SOC 2 Type II certified facilities with 24/7 security monitoring and access controls

Workstation Security

Automatic screen locks, encrypted hard drives, and secure disposal of physical media

Device Controls

Policies governing the use of mobile devices and removal of hardware

Technical Safeguards

Encryption

256-bit SSL/TLS encryption for data in transit and AES-256 encryption for data at rest

Access Controls

Multi-factor authentication, unique user identification, and automatic logoff

Audit Logs

Comprehensive logging of all access to ePHI with regular review and analysis

Integrity Controls

Mechanisms to ensure ePHI is not improperly altered or destroyed

Transmission Security

End-to-end encryption for all video sessions and secure messaging

How We Handle Your Protected Health Information


Permitted Uses and Disclosures

We use and disclose your PHI only for:

  • Treatment: Facilitating care from your healthcare provider
  • Payment: Processing billing and insurance claims
  • Healthcare Operations: Quality improvement, training, and business management
  • Your Authorization: Other uses only with your written consent
  • Legal Requirements: When required by law or court order

Minimum Necessary Standard

We follow the "minimum necessary" standard, using and disclosing only the minimum amount of PHI required to accomplish the intended purpose.

Data Retention

We retain your health information in accordance with federal and state law requirements, typically for a minimum of 6 years after your last activity. You may request deletion of your data subject to legal retention requirements.

Business Associate Agreements


We work with carefully vetted third-party service providers who may have access to your PHI. HIPAA requires us to have Business Associate Agreements (BAAs) with these providers, ensuring they:

  • Implement appropriate safeguards to protect PHI
  • Use and disclose PHI only as permitted
  • Report any security incidents or breaches
  • Ensure their subcontractors comply with HIPAA
  • Return or destroy PHI when services end

Our business associates include:

  • Cloud hosting providers (AWS, Google Cloud Platform)
  • Payment processors (Stripe, Square)
  • Analytics services (with de-identified data only)
  • Email and communication services

Your HIPAA Rights


Under HIPAA, you have the following rights regarding your health information:

Right to Access

You may view and obtain copies of your health records. You can download your records from your account dashboard at any time.

Right to Amend

You may request corrections to your health information if you believe it is inaccurate or incomplete.

Right to an Accounting

You may request a list of certain disclosures of your health information.

Right to Request Restrictions

You may request limitations on how we use or disclose your PHI.

Right to Confidential Communications

You may request communications by alternative means or at alternative locations.

Right to a Paper Copy

You may request a paper copy of our Notice of Privacy Practices at any time.

To exercise any of these rights, please contact our Privacy Officer at sychhealthapp@gmail.com or through your account settings.

Breach Notification Procedures


In the unlikely event of a breach of your unsecured PHI, we will:

Immediate Response

  • Investigate the incident within 24 hours
  • Take immediate steps to mitigate harm
  • Document the breach and remedial actions
  • Report to appropriate authorities

Notification

If a breach affects you, we will notify you:

  • When: Within 60 days of discovering the breach
  • How: By email, mail, or phone
  • What: Description of the breach, types of information involved, steps we're taking, and what you can do to protect yourself

Regulatory Notification

We will also notify the Department of Health and Human Services and, if the breach affects more than 500 individuals, prominent media outlets.

Ongoing Compliance Efforts


HIPAA compliance is an ongoing commitment. We maintain our compliance through:

Regular Assessments

  • Annual HIPAA risk assessments
  • Quarterly security audits
  • Penetration testing and vulnerability scans
  • Third-party security certifications (SOC 2, ISO 27001)

Continuous Improvement

  • Monitoring regulatory updates and guidance
  • Updating policies and procedures
  • Implementing new security technologies
  • Responding to emerging threats

Staff Training

  • HIPAA training for all new employees
  • Annual refresher courses
  • Role-specific training programs
  • Security awareness campaigns

Questions About Our HIPAA Compliance?


If you have questions about our HIPAA compliance practices or wish to file a complaint, please contact:

Privacy Officer

Email: sychhealthapp@gmail.com

Phone: 1-800-SYCH-HELP

Address: Sych Privacy Office, 123 Healthcare Blvd, New York, NY 10001

File a Complaint

If you believe your privacy rights have been violated, you may file a complaint with us or with:

U.S. Department of Health and Human Services
Office for Civil Rights
200 Independence Avenue, S.W.
Washington, D.C. 20201
Phone: 1-877-696-6775
Website: www.hhs.gov/ocr/privacy

No Retaliation: You will not be penalized or retaliated against in any way for filing a complaint.