Orange County NC Website
<br />STRATUS VIDEO INTERPRETING SERVICES <br />AFS – 6/22/2016 Confidential and Proprietary Page 1 of 2 <br />Exhibit C <br />Health Insurance Portability and Accountability Act (HIPAA) <br />Compliance Process <br /> <br />Background <br />The Health Insurance Portability and Accountability Act (HIPAA) governs the documentation and dissemination <br />of all patients' healthcare information by medical providers, insurance companies, and certain third parties <br />(Covered Entities). <br /> <br />HIPAA rules require that Covered Entities and their Business Associates apply appropriate administrative, <br />technical, and physical safeguards to ensure the privacy of Protected Health Information (PHI) and Electronic PHI <br />(EPHI). <br /> <br />HIPAA includes both the Privacy Rule and the Security Rule: <br /> <br />• The Privacy Rule. Gives individuals rights over their health information, whether oral, written or <br />electronic. <br /> <br />• The Security Rule. Protects all health information in electronic form, ensuring that all EPHIs are secure. <br /> <br />There is no governing agency, commission, or standards body that certifies HIPAA compliance. However, <br />Department of Justice is tasked with investigating and adjudicating HIPAA violations by Covered Entity and <br />Business Associates. <br /> <br />It is up to the Covered Entity or Business Associate to determine and maintain it's own compliance with the <br />Privacy and Security rules. <br />Discussion <br />Stratus recognizes that we must provide our services and solutions that are HIPAA complainant and support the <br />requirements outlined in a Business Associate Agreement. Stratus designed and developed our services to <br />operate in accordance with your HIPAA requirements. <br /> <br />Specific Stratus Video Features to ensure HIPAA compliance: <br /> <br />1) Data Security. <br />a) Stratus application is Natively encrypted using WEBRTC to conform with HIPPA requirements. <br /> <br />b) Stratus does not record video calls so no protected health information is captured or stored in the <br />Stratus Video system at any point and as such, fits the definition of data not at rest. <br /> <br />c) Access to Stratus software on the devices is Password Protected <br /> <br />d) Video software does not allow Auto Answer feature, preventing unauthorized access to video calls. <br /> <br />DocuSign Envelope ID: 76B817AA-FF3F-46C9-905E-8E74304FD146