Secure clinical communication for authorized healthcare providers support@sbaralerts.com
Compliance & Safeguards

HIPAA & Security Statement

An overview of administrative, technical, and organizational safeguards supporting secure clinical communication.

Effective July 22, 2026 SBARAlerts Legal & Trust Center
Role-based accessFacility authorizationAudit loggingEncrypted transport

This page explains how SBARAlerts is designed to support secure healthcare workflows. It is not a certification or guarantee of customer compliance.

1Role of SBARAlerts

SBARAlerts may act as a Business Associate when it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity under a signed Business Associate Agreement.

2Administrative Safeguards

Controls may include workforce access procedures, security responsibilities, risk review, incident handling, vendor management, training, contingency planning, and documented policies.

3Technical Safeguards

Controls may include unique user identification, secure authentication, role-based permissions, facility-level authorization, audit logs, TLS encryption, protected storage, session controls, login throttling, and access monitoring.

4Physical and Hosting Safeguards

Production hosting should be provided by vendors willing to execute appropriate agreements and support restricted administrative access, environmental protections, redundancy, backups, and secure media handling.

5Customer Responsibilities

Customers remain responsible for workforce authorization, minimum-necessary access, device security, policy enforcement, emergency workflows, privacy notices, and timely account removal.

6Compliance Limitations

HIPAA-ready is not the same as automatic compliance. Compliance depends on technology, contracts, policies, workforce conduct, configuration, and documented risk management.