HIPAA Policy
Last updated: June 14, 2026
CaseLift is built to handle Protected Health Information (PHI) responsibly. When your practice uses CaseLift to record and analyze patient consultations, your practice is the Covered Entity and CaseLift acts as a Business Associate under the U.S. Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act. This Policy summarizes the safeguards we apply.
1. Our role & scope
We process PHI only on behalf of, and at the direction of, the practices that use the Service, to provide recording, transcription, analysis, and patient follow-up. We do not use or disclose PHI except as permitted by the Business Associate Agreement and applicable law.
2. Administrative safeguards
- Written security policies and assignment of security responsibility.
- Workforce access on a least-privilege, need-to-know basis, with onboarding and periodic security training.
- Periodic risk assessment and remediation of identified risks.
- Business Associate Agreements with subcontractors that may handle PHI.
3. Physical safeguards
PHI is hosted in the United States on reputable cloud infrastructure that maintains physical access controls, environmental protections, and industry-recognized security certifications.
4. Technical safeguards
- Encryption of PHI in transit (TLS) and at rest.
- Access controls with unique user accounts, role-based permissions, and support for multi-factor authentication.
- Audit logging of access to PHI, retained for the periods required by applicable regulations.
- Automatic session expiry and integrity controls to protect against improper alteration or destruction.
5. Minimum necessary
We limit the use, disclosure of, and access to PHI to the minimum necessary to accomplish the intended purpose, consistent with HIPAA.
6. De-identification
Where indicated, the Service removes identifying details from transcripts. De-identified data (which does not identify any individual) is not PHI and may be used to operate and improve the Service consistent with applicable law.
7. Subcontractors & subprocessors
Where we engage vendors that create, receive, maintain, or transmit PHI on our behalf (for hosting, transcription, messaging, or AI analysis), we require them to agree to safeguards at least as protective as those in our Business Associate Agreement.
8. Breach notification
If we discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and within the timeframes required by HIPAA, and we will cooperate with the practice's breach-response obligations.
9. Patient rights
Patients exercise their HIPAA rights (access, amendment, accounting of disclosures, and restrictions) through the practice that treated them. We support practices in fulfilling those requests as required by HIPAA and the Business Associate Agreement.
10. Data location
PHI is stored and processed on infrastructure located in the United States.
11. Report a concern
To request our Business Associate Agreement, report a security concern, or ask about our HIPAA practices, email hello@caselift.io.
