HIPAA Compliance
Your health information is sacred. We are committed to the highest standards of data protection and HIPAA compliance.
Encrypted Data
All health data is encrypted in transit and at rest using AES-256 encryption.
Access Controls
Strict role-based access ensures only authorized personnel can view PHI.
Secure Infrastructure
HIPAA-compliant cloud infrastructure with continuous monitoring.
Our Commitment to HIPAA
Marqi Medical is committed to ensuring the confidentiality, integrity, and availability of all Protected Health Information (PHI) we receive, maintain, process, or transmit. We comply with the Health Insurance Portability and Accountability Act (HIPAA) of 1996, including the Privacy Rule, Security Rule, and Breach Notification Rule.
Protected Health Information (PHI)
PHI includes any individually identifiable health information that we create, receive, maintain, or transmit. This includes:
- Health assessment results and quiz responses
- Medical history and health records shared with us
- Communications between you and our healthcare providers
- Billing and payment information related to health services
- Any information that can be used to identify a patient
Administrative Safeguards
- Designated HIPAA Privacy and Security Officers
- Regular workforce training on HIPAA policies and procedures
- Comprehensive risk assessments conducted annually
- Documented policies and procedures for handling PHI
- Business Associate Agreements (BAAs) with all service providers
- Incident response and breach notification procedures
Technical Safeguards
- AES-256 encryption for data at rest and TLS 1.3 for data in transit
- Multi-factor authentication for all system access
- Automatic session timeouts and audit logging
- Regular vulnerability scanning and penetration testing
- Secure backup and disaster recovery procedures
- Network segmentation and intrusion detection systems
Physical Safeguards
- Restricted physical access to facilities containing PHI
- Secure workstation policies and device management
- Proper disposal procedures for PHI-containing media
- Environmental controls and monitoring
Breach Notification
In the unlikely event of a data breach involving PHI, Marqi Medical will comply with all HIPAA Breach Notification Rule requirements. Affected individuals will be notified within 60 days of discovery. Breaches affecting 500 or more individuals will be reported to the U.S. Department of Health and Human Services and prominent media outlets as required by law.
Your Patient Rights
Under HIPAA, you have the right to:
- Access and obtain a copy of your health records
- Request corrections to your health information
- Receive an accounting of disclosures of your PHI
- Request restrictions on certain uses and disclosures
- Request confidential communications
- File a complaint if you believe your rights have been violated
HIPAA Inquiries
For questions about our HIPAA compliance practices or to exercise your patient rights, contact our Privacy Officer at: admin@marqimedical.com or call (888) 884-4070.