Overview
For US-based dermatology and aesthetic practices, the Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. This guide explains how Dermi Atlas Professional acts as a technical tool to support compliance with the HIPAA Security Rule.
Dermi and the Business Associate Relationship
Under HIPAA, a Business Associate is a vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity.
Because Dermi Atlas Professional is deployed on the practice's own infrastructure and stores PHI locally, Dermi Inc. does not access PHI as part of normal operations. The full description of Dermi's role and the data Dermi processes is set out in the Dermi Privacy Policy, the Dermi Atlas Professional EULA, and the Dermi Sub-Processors document. Practices should consult their privacy officer or counsel for the resulting determination under HIPAA.
Mapping Features to HIPAA Standards
The following sections outline how Dermi Atlas Professional features align with specific categories of the HIPAA Security Rule.
1. Access Control
Standard: Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights.
Dermi Atlas Features:
- Unique User Identification: Every user has a distinct username and password.
- Logical Isolation: Users cannot view patient records belonging to other users on the same system.
- Automatic Logoff: Users can end all active sessions across devices from Options => Account. Session lifetime is set in the deployment configuration rather than in the Dermi Atlas Manager interface.
- Encryption: Passwords are hashed; data in transit is encrypted via HTTPS.
2. Audit Controls
Standard: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
Dermi Atlas Features:
- Configurable Logging: "Comprehensive" logging mode tracks creation, viewing, updating, and deletion of patient records and images.
- Granular Detail: Logs record the acting account, the operation, the affected resource, and the timestamp of each event. Authentication and account events additionally record IP address, user agent, and timezone.
- Retention: Audit logs are preserved in the local database and included in system backups.
3. Integrity
Standard: Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.
Dermi Atlas Features:
- Confirmation Workflows: Deletion requires typed confirmation phrases before proceeding. The Data Deletion Policy, configured in Dermi Atlas Manager, determines whether deletion is reversible (Recoverable or Standard) or permanent (Permanent). Recoverable and Standard deletion policies retain data for a configurable period, during which deleted patients, entries, and images can be recovered from within Dermi Atlas Professional.
- Backup Verification: System backups use checksums to verify data integrity during restoration.
4. Transmission Security
Standard: Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.
Dermi Atlas Features:
- Local HTTPS: Dermi Atlas Manager supplies the certificate configuration and the Network Gateway container generates the self-signed certificate at startup, encrypting traffic between the host computer and tablets or laptops on the local network.
Incident Response
HIPAA requires Covered Entities to have procedures for responding to security incidents.
How Dermi Atlas Supports Response:
In the event of a suspected security incident (e.g., a lost tablet or suspected insider threat), Dermi Atlas Professional's audit logs provide the forensic data necessary to determine:
- Which patient records were accessed.
- Whether data was exported or viewed.
- The timeframe of the unauthorized access.
Checklist for Administrators
To maximize HIPAA compliance when using Dermi Atlas Professional, ensure the following steps are taken:
- Confirm Comprehensive Logging: Audit Logging ships set to "Comprehensive"; confirm it has not been changed to "Essential" in Dermi Atlas Manager under Options => Advanced, so that a complete audit trail is available for potential investigations.
- Secure the Host: Enable full-disk encryption (BitLocker/FileVault) on the computer running the software to protect data at rest.
- Network Security: Configure the host firewall to allow traffic only from trusted devices and ensure the local Wi-Fi is WPA2/WPA3 encrypted.
- Backup Strategy: Configure a routine to move Dermi Atlas backups to a secure, encrypted, off-site location.
- Access Review: Periodically review the user list and disable accounts for former staff members immediately.
Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Compliance is the responsibility of the practice.
Related Resources
- Security and Compliance Fundamentals for a broader overview of the platform's security posture.
- Audit Logging Configuration for configuring and reviewing activity logs.
- PIPEDA Compliance Guide for Canadian privacy regulation guidance.
- Managing Patients for consent tracking and patient record management.