Learn how Dermi Atlas Professional's features map to HIPAA Security Rule standards to support your compliance efforts.
For US-based dermatology and aesthetic practices, the Health Insurance Portability and Accountability Act (HIPAA) sets the standard for protecting sensitive patient data. This guide explains how Dermi Atlas Professional acts as a technical tool to support your compliance with the HIPAA Security Rule.
Under HIPAA, a Business Associate is a vendor that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity.
Dermi is not a Business Associate.
Because Dermi Atlas Professional is self-hosted software, Dermi Inc. does not have access to your PHI. The data resides entirely on your local hardware. Consequently, Dermi does not sign a Business Associate Agreement (BAA). Your practice retains sole custody of the data.
The following sections outline how Dermi Atlas Professional features align with specific categories of the HIPAA Security Rule.
Standard: Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to those persons or software programs that have been granted access rights.
Dermi Atlas Features:
Standard: Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information.
Your feedback helps us improve our documentation
Contact our support team for personalized help
Dermi Atlas Features:
Standard: Implement policies and procedures to protect electronic protected health information from improper alteration or destruction.
Dermi Atlas Features:
Standard: Implement technical security measures to guard against unauthorized access to electronic protected health information that is being transmitted over an electronic communications network.
Dermi Atlas Features:
HIPAA requires Covered Entities to have procedures for responding to security incidents.
How Dermi Atlas Supports Response:
In the event of a suspected security incident (e.g., a lost tablet or suspected insider threat), Dermi Atlas Professional's audit logs provide the forensic data necessary to determine:
To maximize HIPAA compliance when using Dermi Atlas Professional, ensure the following steps are taken:
Disclaimer: This guide is for informational purposes only and does not constitute legal advice. Compliance is the responsibility of the practice.