HIPAA Compliance
Protecting Your Medical Information with Industry-Leading Standards
Vest Safety Medical Services is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA) and implements comprehensive safeguards to protect Protected Health Information (PHI). Our commitment to HIPAA compliance ensures that your medical information is handled with the highest level of security and confidentiality.
Our HIPAA Commitment
As a covered entity under HIPAA, VestMed is legally obligated to protect the privacy and security of your health information. We have implemented a comprehensive HIPAA compliance program that includes:
- Detailed policies and procedures for PHI handling and protection
- Regular risk assessments and security audits
- Ongoing staff training on HIPAA requirements and best practices
- Business Associate Agreements with all third-party service providers
- Incident response and breach notification procedures
- Patient rights management and request handling processes
Protected Health Information (PHI)
What PHI We Collect
We collect and process PHI necessary for respiratory clearance evaluations:
- Medical questionnaire responses about respiratory health conditions
- Pulmonary function test results and spirometry measurements
- Medical clearance determinations and physician review notes
- Fit test records and respirator specifications
- Historical medical evaluation records
- Demographic information linked to health records
Minimum Necessary Standard
We adhere to the HIPAA "minimum necessary" standard, collecting and sharing only the PHI required to accomplish the intended purpose. Our systems are designed to limit access to PHI based on user roles and business need.
De-Identification
For research, analytics, and quality improvement, we use de-identified data that has had all identifying information removed in accordance with HIPAA de-identification standards.
HIPAA Security Safeguards
HIPAA requires three types of safeguards to protect PHI. We implement comprehensive measures in each category:
Administrative Safeguards
- Security Management: Formal security policies, risk assessments, and mitigation strategies
- Workforce Security: Background checks, role-based access, and termination procedures
- Training: Annual HIPAA training for all staff members
- Oversight: Designated Privacy Officer and Security Officer
- Contingency Planning: Data backup, disaster recovery, and business continuity plans
- Business Associates: Signed agreements with all vendors handling PHI
Physical Safeguards
- Facility Access: Secure data centers with 24/7 monitoring and access controls
- Workstation Security: Secure workstations with automatic screen locks and encryption
- Device Controls: Encrypted mobile devices with remote wipe capabilities
- Media Disposal: Secure destruction of physical media containing PHI
- Environmental Controls: Fire suppression, climate control, and power redundancy
Technical Safeguards
- Access Controls: Unique user IDs, automatic logoff, and emergency access procedures
- Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
- Audit Controls: Comprehensive logging of all PHI access and modifications
- Integrity Controls: Mechanisms to ensure PHI is not improperly altered or destroyed
- Authentication: Multi-factor authentication for all user accounts
- Transmission Security: Secure protocols for all electronic PHI transmissions
HIPAA Privacy Rule Compliance
Notice of Privacy Practices
Our Privacy Policy serves as our Notice of Privacy Practices, explaining how we use and disclose PHI, and your rights regarding your health information.
Permitted Uses and Disclosures
We use and disclose PHI only for:
- Treatment: Medical evaluation and clearance determinations by our physicians
- Payment: Billing and payment processing for our services
- Healthcare Operations: Quality improvement, training, and business management
- Required by Law: Compliance with legal obligations and court orders
- With Authorization: Other uses only with your written authorization
Employer Access Limitations
HIPAA strictly limits what information employers can access. We provide employers only with:
- Clearance status (approved, denied, or conditional)
- Any work restrictions or accommodations required
- Compliance documentation for regulatory purposes
We do NOT disclose medical details, specific conditions, questionnaire responses, or other PHI to employers without your authorization.
Your HIPAA Rights
Under HIPAA, you have the following rights regarding your PHI:
Right to Access
Request and receive copies of your medical records
Right to Amend
Request corrections to inaccurate or incomplete information
Right to Accounting
Receive a list of certain disclosures we've made
Right to Restrict
Request limitations on uses and disclosures of PHI
Right to Confidential Communications
Request communications by alternative means or locations
Right to Complain
File complaints about potential privacy violations
To Exercise Your Rights:
Email: privacy@vestmed.com
Phone: 844-837-8767
Response Time: We will respond within 30 days of receiving your request
Breach Notification
In the unlikely event of a breach of unsecured PHI, we follow HIPAA's Breach Notification Rule:
- Risk Assessment: Immediate evaluation of potential harm to individuals
- Individual Notification: Written notice within 60 days to affected individuals
- Media Notification: Public notice if breach affects 500+ individuals in a jurisdiction
- HHS Notification: Report to Department of Health and Human Services
- Remediation: Immediate steps to mitigate harm and prevent recurrence
To date, VestMed has maintained a perfect record with zero reportable breaches of PHI.
Business Associate Agreements
HIPAA requires us to have Business Associate Agreements (BAAs) with any third party that handles PHI on our behalf:
Our Business Associates
- Cloud hosting and infrastructure providers
- Email and communication services
- Backup and disaster recovery services
- IT support and managed services providers
BAA Requirements
All BAAs include provisions requiring business associates to:
- Implement appropriate safeguards to protect PHI
- Report any security incidents or breaches
- Ensure their subcontractors also comply with HIPAA
- Return or destroy PHI at termination of services
- Permit audits and provide compliance documentation
For Employers Using Vest
If your organization requires a Business Associate Agreement with VestMed, our legal team will provide one. Contact us at legal@vestmed.com to request a BAA.
Staff Training and Awareness
All VestMed employees receive comprehensive HIPAA training:
- Initial HIPAA training during onboarding
- Annual refresher training on privacy and security rules
- Role-specific training for staff with PHI access
- Security awareness training on phishing and social engineering
- Incident response and breach notification procedures
- Regular updates on regulatory changes and best practices
Staff who violate HIPAA policies are subject to disciplinary action, up to and including termination.
Certifications and Audits
We maintain industry-leading certifications and undergo regular audits:
Security Audits
Regular third-party security assessments
HIPAA Audits
Regular internal and external audits
Medical Review
Licensed physicians ensure compliance
For more information about our security measures, visit our Security page.
Reporting HIPAA Concerns
If you believe your privacy rights have been violated or have concerns about our privacy practices:
File a Complaint with Vest
Privacy Officer: VestMed
Email: privacy@vestmed.com
Phone: 844-837-8767
File a Complaint with HHS
Office for Civil Rights (OCR)
U.S. Department of Health and Human Services
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
Phone: 1-800-368-1019
You will not be retaliated against for filing a complaint.
Questions About HIPAA Compliance?
Our privacy team is available to answer questions about how we protect your health information and comply with HIPAA regulations.
Contact Privacy Team