Orange County NC Website
DocuSign Envelope ID:C3ACE658-720C-402F-AE1C-C7B9F4726DB6 <br /> (,,'STRATUS 11 I <br /> STRATUS VIDEO INTERPRETING SERVICES <br /> Exhibit C <br /> Health Insurance Portability and Accountability Act (HIPAA) <br /> Compliance Process <br /> Background <br /> The Health Insurance Portability and Accountability Act (HIPAA) governs the documentation and dissemination <br /> of all patients' healthcare information by medical providers, insurance companies, and certain third parties <br /> (Covered Entities). <br /> HIPAA rules require that Covered Entities and their Business Associates apply appropriate administrative, <br /> technical, and physical safeguards to ensure the privacy of Protected Health Information (PHI) and Electronic PHI <br /> (EPHI). <br /> HIPAA includes both the Privacy Rule and the Security Rule: <br /> • The Privacy Rule. Gives individuals rights over their health information, whether oral, written or <br /> electronic. <br /> • The Security Rule. Protects all health information in electronic form, ensuring that all EPHIs are secure. <br /> There is no governing agency, commission, or standards body that certifies HIPAA compliance. However, <br /> Department of Justice is tasked with investigating and adjudicating HIPAA violations by Covered Entity and <br /> Business Associates. <br /> It is up to the Covered Entity or Business Associate to determine and maintain it's own compliance with the <br /> Privacy and Security rules. <br /> Discussion <br /> Stratus recognizes that we must provide our services and solutions that are HIPAA complainant and support the <br /> requirements outlined in a Business Associate Agreement. Stratus designed and developed our services to <br /> operate in accordance with your HIPAA requirements. <br /> Specific Stratus Video Features to ensure HIPAA compliance: <br /> 1) Data Security. <br /> a) Stratus application is Natively encrypted using WEBRTC to conform with HIPPA requirements. <br /> b) Stratus does not record video calls so no protected health information is captured or stored in the <br /> Stratus Video system at any point and as such,fits the definition of data not at rest. <br /> c) Access to Stratus software on the devices is Password Protected <br /> d) Video software does not allow Auto Answer feature, preventing unauthorized access to video calls. <br /> AFS—6/22/2016 Confidential and Proprietary Page 1 of 2 <br />