ACPlus®

Security and HIPAA Compliance

This page contains the ACPlus® application security overview. The goal of this page is to provide a high-level overview of encryption and security methods installed across the entire ACPlus® platform to ensure HIPAA compliancy.


DATA PRIVACY

LOCATION TRACKING

STORING PERSONAL INFORMATION AND CACHE MANAGEMENT

USER ACCOUNTS AND PASSWORDS SECURITY

DATA TRANSMISSION AND PROTECTION

HIPAA COMPLIANT

ACPlus® Frequently Asked Questions (HIPAA Privacy and Security)

1. What are the safeguards that allow therapists to access ACPlus® using their personal devices?

The ACPlus® app is designed so that no patient information is stored locally on any device that uses the app.

2. How is ePHI protected if I take a picture with the camera on my iPad or iPhone using the ACPlus® app?

Images taken on the ACPlus® application while using an iPad or iPhone are automatically sent securely to the encrypted ACPlus® cloud.

3. How is ACPlus® used for telehealth care or consultation and what precautions should users can take?

ACPlus® uses non-public facing, remote communication app Twilio for telehealth consultations. Twilio is HIPAA compliant.

4. How is ACPlus® assigned to a user and should that access be shared?

ACPlus® requires all users with authorized access (including employees) to have an individual login account.

5. How does the HIPAA rule allow health care providers to use mobile devices to access ePHI in a cloud?

Health care providers, other covered entities, and business associates may use mobile devices to access (ePHI) in a cloud as long as:

Data backup and storage

6.1 How and how often is ePHI backed up to prevent data loss?

ACPlus® uses the AWS RDS database for data storage.

6.2 Where is this backed up data stored and who has access to it?

Using the backup file, the database with ePHI can be restored or rolled back to the prior version within the 35-day backup retention period.

Storage of ePHI

7.1 How is ePHI be stored?

The stored data is encrypted, de-identified and made unreadable, thus HIPAA compliant.

Audit controls

8.1 Who has access to the data other than individual users?

Nobody has access to the data other than individual users.

8.2 How are user logins monitored?

ACPlus® also maintains a secure custom event logging system that displays the user level logs at the Facility Portal.

ACPlus® User Dos & Don’ts

DO

  • Log in to ACPlus® using your unique user account
  • Logout of ACPlus® when not actively using the application
  • Be sure to follow all HIPAA guidelines when using the ACPlus® application
  • Assure that when reviewing or accessing patient information (ePHI), that only you can visually or audibly review the ePHI.
  • Be aware of your surroundings for others looking over your shoulder when viewing ePHI

DON’T

  • Share log in information or password with any other user
  • Leave your device unattended at any time
  • Screen shot copy, or share any ePHI from the ACPlus® application
  • Email any ePHI from ACPlus® without consulting your company’s HIPAA guidelines first
  • Use other third party, public facing applications (as discussed above) to transmit or communicate any ePHI.