This page explains how SBARAlerts is designed to support secure healthcare workflows. It is not a certification or guarantee of customer compliance.
1Role of SBARAlerts
SBARAlerts may act as a Business Associate when it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity under a signed Business Associate Agreement.
2Administrative Safeguards
Controls may include workforce access procedures, security responsibilities, risk review, incident handling, vendor management, training, contingency planning, and documented policies.
3Technical Safeguards
Controls may include unique user identification, secure authentication, role-based permissions, facility-level authorization, audit logs, TLS encryption, protected storage, session controls, login throttling, and access monitoring.
4Physical and Hosting Safeguards
Production hosting should be provided by vendors willing to execute appropriate agreements and support restricted administrative access, environmental protections, redundancy, backups, and secure media handling.
5Customer Responsibilities
Customers remain responsible for workforce authorization, minimum-necessary access, device security, policy enforcement, emergency workflows, privacy notices, and timely account removal.