Skip to content
VestMed

HIPAA Compliance

Protecting Your Medical Information with Industry-Leading Standards

Vest Safety Medical Services is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA) and implements comprehensive safeguards to protect Protected Health Information (PHI). Our commitment to HIPAA compliance ensures that your medical information is handled with the highest level of security and confidentiality.

Our HIPAA Commitment

As a covered entity under HIPAA, VestMed is legally obligated to protect the privacy and security of your health information. We have implemented a comprehensive HIPAA compliance program that includes:

  • Detailed policies and procedures for PHI handling and protection
  • Regular risk assessments and security audits
  • Ongoing staff training on HIPAA requirements and best practices
  • Business Associate Agreements with all third-party service providers
  • Incident response and breach notification procedures
  • Patient rights management and request handling processes

Protected Health Information (PHI)

What PHI We Collect

We collect and process PHI necessary for respiratory clearance evaluations:

  • Medical questionnaire responses about respiratory health conditions
  • Pulmonary function test results and spirometry measurements
  • Medical clearance determinations and physician review notes
  • Fit test records and respirator specifications
  • Historical medical evaluation records
  • Demographic information linked to health records

Minimum Necessary Standard

We adhere to the HIPAA "minimum necessary" standard, collecting and sharing only the PHI required to accomplish the intended purpose. Our systems are designed to limit access to PHI based on user roles and business need.

De-Identification

For research, analytics, and quality improvement, we use de-identified data that has had all identifying information removed in accordance with HIPAA de-identification standards.

HIPAA Security Safeguards

HIPAA requires three types of safeguards to protect PHI. We implement comprehensive measures in each category:

Administrative Safeguards

  • Security Management: Formal security policies, risk assessments, and mitigation strategies
  • Workforce Security: Background checks, role-based access, and termination procedures
  • Training: Annual HIPAA training for all staff members
  • Oversight: Designated Privacy Officer and Security Officer
  • Contingency Planning: Data backup, disaster recovery, and business continuity plans
  • Business Associates: Signed agreements with all vendors handling PHI

Physical Safeguards

  • Facility Access: Secure data centers with 24/7 monitoring and access controls
  • Workstation Security: Secure workstations with automatic screen locks and encryption
  • Device Controls: Encrypted mobile devices with remote wipe capabilities
  • Media Disposal: Secure destruction of physical media containing PHI
  • Environmental Controls: Fire suppression, climate control, and power redundancy

Technical Safeguards

  • Access Controls: Unique user IDs, automatic logoff, and emergency access procedures
  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Audit Controls: Comprehensive logging of all PHI access and modifications
  • Integrity Controls: Mechanisms to ensure PHI is not improperly altered or destroyed
  • Authentication: Multi-factor authentication for all user accounts
  • Transmission Security: Secure protocols for all electronic PHI transmissions

HIPAA Privacy Rule Compliance

Notice of Privacy Practices

Our Privacy Policy serves as our Notice of Privacy Practices, explaining how we use and disclose PHI, and your rights regarding your health information.

Permitted Uses and Disclosures

We use and disclose PHI only for:

  • Treatment: Medical evaluation and clearance determinations by our physicians
  • Payment: Billing and payment processing for our services
  • Healthcare Operations: Quality improvement, training, and business management
  • Required by Law: Compliance with legal obligations and court orders
  • With Authorization: Other uses only with your written authorization

Employer Access Limitations

HIPAA strictly limits what information employers can access. We provide employers only with:

  • Clearance status (approved, denied, or conditional)
  • Any work restrictions or accommodations required
  • Compliance documentation for regulatory purposes

We do NOT disclose medical details, specific conditions, questionnaire responses, or other PHI to employers without your authorization.

Your HIPAA Rights

Under HIPAA, you have the following rights regarding your PHI:

Right to Access

Request and receive copies of your medical records

Right to Amend

Request corrections to inaccurate or incomplete information

Right to Accounting

Receive a list of certain disclosures we've made

Right to Restrict

Request limitations on uses and disclosures of PHI

Right to Confidential Communications

Request communications by alternative means or locations

Right to Complain

File complaints about potential privacy violations

To Exercise Your Rights:

Email: privacy@vestmed.com
Phone: 844-837-8767
Response Time: We will respond within 30 days of receiving your request

Breach Notification

In the unlikely event of a breach of unsecured PHI, we follow HIPAA's Breach Notification Rule:

  • Risk Assessment: Immediate evaluation of potential harm to individuals
  • Individual Notification: Written notice within 60 days to affected individuals
  • Media Notification: Public notice if breach affects 500+ individuals in a jurisdiction
  • HHS Notification: Report to Department of Health and Human Services
  • Remediation: Immediate steps to mitigate harm and prevent recurrence

To date, VestMed has maintained a perfect record with zero reportable breaches of PHI.

Business Associate Agreements

HIPAA requires us to have Business Associate Agreements (BAAs) with any third party that handles PHI on our behalf:

Our Business Associates

  • Cloud hosting and infrastructure providers
  • Email and communication services
  • Backup and disaster recovery services
  • IT support and managed services providers

BAA Requirements

All BAAs include provisions requiring business associates to:

  • Implement appropriate safeguards to protect PHI
  • Report any security incidents or breaches
  • Ensure their subcontractors also comply with HIPAA
  • Return or destroy PHI at termination of services
  • Permit audits and provide compliance documentation

For Employers Using Vest

If your organization requires a Business Associate Agreement with VestMed, our legal team will provide one. Contact us at legal@vestmed.com to request a BAA.

Staff Training and Awareness

All VestMed employees receive comprehensive HIPAA training:

  • Initial HIPAA training during onboarding
  • Annual refresher training on privacy and security rules
  • Role-specific training for staff with PHI access
  • Security awareness training on phishing and social engineering
  • Incident response and breach notification procedures
  • Regular updates on regulatory changes and best practices

Staff who violate HIPAA policies are subject to disciplinary action, up to and including termination.

Certifications and Audits

We maintain industry-leading certifications and undergo regular audits:

Security Audits

Regular third-party security assessments

HIPAA Audits

Regular internal and external audits

Medical Review

Licensed physicians ensure compliance

For more information about our security measures, visit our Security page.

Reporting HIPAA Concerns

If you believe your privacy rights have been violated or have concerns about our privacy practices:

File a Complaint with Vest

Privacy Officer: VestMed
Email: privacy@vestmed.com
Phone: 844-837-8767

File a Complaint with HHS

Office for Civil Rights (OCR)
U.S. Department of Health and Human Services
Website: www.hhs.gov/ocr/privacy/hipaa/complaints/
Phone: 1-800-368-1019

You will not be retaliated against for filing a complaint.

Questions About HIPAA Compliance?

Our privacy team is available to answer questions about how we protect your health information and comply with HIPAA regulations.

Contact Privacy Team