top of page

HIPAA COMPLIANCE STATEMENT
HIPAA stands for the Health Insurance Portability and Accountability Act that was enacted in 1996 to help protect individuals' personal health information (PHI). The HIPAA Privacy Rule and the Security Rule were put in place in 2003 to provide standards for safeguarding an individual's PHI from unauthorized individuals. This is the HIPAA compliance statement for Convergence Case Management Data Retrieval Software, LLC.

Convergence is encryptable software that may greatly assist a covered entity or business associate with its HIPAA compliance if used properly. The software logs all user activity and record views, and chronicles the backup of data changes. Convergence settings can be changed to modify both who has access to data and how much data can be viewed. The software also provides comprehensive user activity reports. Documents uploaded to Convergence may only be accessed by providing valid login credentials. The Convergence system’s security controls require a strong password.

Therefore, Convergence is capable of functioning as a HIPAA compliant database system and improving compliance with HIPAA requirements by controlling access to PHI. However, the Convergence customer must also comply with other HIPAA requirements. Those requirements are extensive and can be found on the Department of Health and Human Services Office of Civil Rights’ website: http://www.hhs.gov/ocr/privacy.

With respect to maximizing the privacy and security capabilities of the software, the customer must ensure that it hosts data on a HIPAA compliant server, carries a SSL encryption certificate and sets up a database backup plan to prevent data loss. It is also necessary for customers to create and secure strong passwords for Convergence users to access data. Convergence provides tools and assistance to help with these things, but Convergence Case Management Partners LLC cannot be held responsible for implementation of HIPAA controls by the end user. The Convergence customer is also solely responsible for the safety of files downloaded from the Convergence server to customer computers, and for handling any "Business Associate" contracts required by HIPAA for data sharing.

 

Because Convergence Case Management Partners LLC will not have access to customer systems or data records, it is not subject to HIPAA regulations as either a covered entity or business associate.

bottom of page