Is SparkPost HIPAA Compliant?
SparkPost is not HIPAA compliant because the terms and conditions of the now rebranded service prohibit violations of “any legal, regulatory, self-regulatory, governmental, statutory requirements of codes of practice”. As SparkPost lacks the safeguards to comply with HIPAA, any use of the service that discloses Protected Health Information (PHI) would be a violation of HIPAA. SparkPost is an email service that enables customers to automate email processes (i.e., welcome emails), develop multi-step email campaigns, and send targeted bulk emails based on customer behaviors. Since the brand’s acquisition by MessageBird in April 2021, customers have also been able to take advantage of SMS marketing, WhatsApp marketing, and social media marketing capabilities. The service’s appeal is likely to increase in the coming months following the announcement that MessageBird is being rebranded as Bird.com and reducing its pricing to below that of its main U.S. rivals. The motive behind the rebranding exercise is rumored to be an attempt to get a bigger foothold in the U.S. market for the...
What Does HHS OIG Stand For?
The initials HHS OIG stand for the U.S. Department of Health and Human Services (HHS) Office of Inspector General (OIG) – the largest civilian Office of Inspector General within the Federal government, with approximately 1,570 auditors, investigators, and evaluators overseeing the Department of Health and Human Services’ $2 trillion portfolio of programs. The HHS OIG was the first civilian Office of Inspector General to be established in 1976 at a time when the Department of Health and Human Services was known as the Department of Health, Education, and Welfare. The Department’s name changed in 1979 when its education functions were transferred to the newly created Department of Education, but remained the same in 1995 when the responsibility for social welfare was transferred to the independent Social Security Administration. What Does HHS OIG Stand For in Terms of Mission? Under the Inspector General Act of 1978, what HHS OIG stands for in terms of mission is two-fold. Its first mission is to protect the integrity of HHS programs and well-being of program beneficiaries. This...
Is Facebook Messenger HIPAA Compliant?
Facebook Messenger is not HIPAA compliant and cannot be used to collect or disclose Protected Health Information (PHI) unless a patient who is the subject of the PHI has requested to communicate via the messaging app. Even in these circumstances, precautions must be taken to prevent impermissible disclosures of PHI. Facebook Messenger is a popular messaging app through which individuals and groups can chat, call, and video each other. In the healthcare industry, the Facebook Messenger for Business service can be used to raise public awareness about health issues, tackle misinformation, promote citizen engagement, and communicate emergency situations or critical incidents. However, personal messaging between healthcare providers and individual patients is not permitted by HIPAA when messages include PHI. This is because Facebook Messenger does not meet the requirements to be a business associate, and has “persistent access” to PHI (even when messages are encrypted), so is not exempted from HIPAA compliance under the Conduit Exception Rule. Is it Possible to Make Facebook Messenger...
Is Zendesk HIPAA Compliant?
Zendesk is HIPAA compliant for covered services in HIPAA-enabled Service Plans, provided organizations agree to the terms of Zendesk’s Business Associate Agreement and configure services to comply with Zendesk’s Security Configuration Requirements. Depending on how the platform is used, it may also be necessary to disable third party apps and integrations, or enter into separate Business Associate Agreements with third party software vendors. Zendesk is a customer experience platform that was originally designed as a customer service solution but now also includes sales, customer management, and workforce productivity services. By default, Zendesk is not HIPAA compliant because it prohibits customers from storing or transmitting Protected Health Information (PHI) under §2.3 of the Main Services Agreement unless “expressly agreed to otherwise by Zendesk in writing”. However, because many customers want to use the platform to create, collect, store, or transmit PHI, Zendesk provides a number of options for overcoming this prohibition. These include subscribing to a HIPAA-enabled...
Healthcare Compliance Program Policies and Procedures
Healthcare compliance program policies and procedures should consist of a combination of policies and procedures mandated by federal, state, and local regulations, and policies and procedures implemented in response to a risk assessment or other corporate activity. There are no “one-size-fits-all” policies and procedures for healthcare compliance programs. Healthcare compliance programs are essential for ensuring organizations comply with all federal, state, and local regulations applicable to their activities, industry best practices, and voluntary standards. Key to the effectiveness of a healthcare compliance program are policies and procedures that instruct workforce members how to perform their functions within the boundaries of the program and how to respond to specific events. Most federal, state, and local regulations have policy and procedure requirements. However, while some are direct requirements, others are indirect requirements. For example, in the HIPAA Privacy Rule there is only one direct requirement – to implement policies and procedures limiting requests...



