Is Zendesk HIPAA Compliant?
Zendesk is HIPAA compliant for covered services in HIPAA-enabled Service Plans, provided organizations agree to the terms of Zendesk’s Business Associate Agreement and configure services to comply with Zendesk’s Security Configuration Requirements. Depending on how the platform is used, it may also be necessary to disable third party apps and integrations, or enter into separate Business Associate Agreements with third party software vendors. Zendesk is a customer experience platform that was originally designed as a customer service solution but now also includes sales, customer management, and workforce productivity services. By default, Zendesk is not HIPAA compliant because it prohibits customers from storing or transmitting Protected Health Information (PHI) under §2.3 of the Main Services Agreement unless “expressly agreed to otherwise by Zendesk in writing”. However, because many customers want to use the platform to create, collect, store, or transmit PHI, Zendesk provides a number of options for overcoming this prohibition. These include subscribing to a HIPAA-enabled...
Healthcare Compliance Program Policies and Procedures
Healthcare compliance program policies and procedures should consist of a combination of policies and procedures mandated by federal, state, and local regulations, and policies and procedures implemented in response to a risk assessment or other corporate activity. There are no “one-size-fits-all” policies and procedures for healthcare compliance programs. Healthcare compliance programs are essential for ensuring organizations comply with all federal, state, and local regulations applicable to their activities, industry best practices, and voluntary standards. Key to the effectiveness of a healthcare compliance program are policies and procedures that instruct workforce members how to perform their functions within the boundaries of the program and how to respond to specific events. Most federal, state, and local regulations have policy and procedure requirements. However, while some are direct requirements, others are indirect requirements. For example, in the HIPAA Privacy Rule there is only one direct requirement – to implement policies and procedures limiting requests...
Security Breaches in Healthcare in 2023
Report: Security Breaches in Healthcare (Direct Download PDF, 1.9MB, 16 pages) An unwanted record was set in 2023 with 725 large security breaches in healthcare reported to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR), beating the record of 720 healthcare security breaches set the previous year. Aside from 2015, the number of reported security breaches in healthcare has increased every year although the rate of increase is slowing and 2024 could see the healthcare industry start to turn the corner. As the chart shows, healthcare security breaches are occurring twice as often as in 2017/2018, with two large healthcare data breaches reported each day on average in 2023. Just a few years ago it was alarming that large healthcare data security breaches were being reported at a rate of one a day. Little did we know how bad the situation would get in such a short space of time. Cybersecurity Training for Healthcare Employees Because most HIPAA breaches stem from human error, our Cybersecurity Training teaches staff how attackers actually...
Interview: Ty Allen, Founder & CEO, SocialClimb
The HIPAA Journal has spoken with Ty Allen, Founder & CEO of SocialClimb. SocialClimb offers a comprehensive, HIPAA-compliant healthcare marketing platform that aligns with the goals of healthcare organizations of all types and sizes. Tell the readers about your career in the healthcare industry I have been building marketing software for years and focused on healthcare marketing software beginning in 2016. I had not previously been in the healthcare space, but quickly discovered that it aligns with my passion for building innovative products that deliver real value. SocialClimb delivers the most comprehensive suite of healthcare marketing tools in an easy-to-use platform, making it easier for doctors to connect with patients in need. What are the main challenges in your position? With HIPAA regulations on the forefront of every healthcare professional’s mind, many organizations are hesitant to implement any form of digital marketing. The challenge we primarily face is educating customers on the importance of marketing and the opportunities available. Healthcare is a...
Is Mandrill HIPAA Compliant?
Mandrill is not HIPAA compliant and cannot be used by HIPAA covered entities or business associates to send transactional emails that contain Protected Health Information (PHI) as the service does not support user compliance with HIPAA. In addition, Mandrill’s parent company – Mailchimp – will not enter into Business Associate Agreements with customers. Mandrill is a transactional email service that can be used as part of the Mailchimp platform to send “transactional” emails – emails that are triggered by events such as an account creation (welcome email), the placement of an order (order confirmation), support enquiries (acknowledgement of enquiry), and password reset requests. Transactional emails do not usually use or disclosure PHI because names and email addresses are not considered PHI under HIPAA when they are maintained in a separate database from individually identifiable health information. If this were the case with Mandrill, the answer to the question is Mandrill HIPAA compliant would be it doesn’t have to be because the service is not using or disclosing PHI. However,...



