1 · Our role
When a healthcare provider deploys MouthLab or the AIDAR Atlas platform, AIDAR acts as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA). We handle PHI only on behalf of, and under instructions from, the covered provider, under a written Business Associate Agreement (BAA).
2 · How we may use and disclose PHI
Subject to the BAA and HIPAA, we use and disclose PHI to perform the services the covered provider has engaged us to perform: capturing physiologic measurements, supporting clinical workflows, generating intelligence outputs, providing 24/7 clinical monitoring (AIDAR Ally), and producing billing-eligible documentation. We apply the minimum necessary standard, using and disclosing only the PHI needed for the task at hand. We do not use or disclose PHI for our own marketing and we do not sell PHI. Where the applicable BAA permits, we may de-identify data in accordance with the HIPAA de-identification standard; once properly de-identified, that data is no longer PHI.
3 · Safeguards
We maintain administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI, including encryption in transit and at rest, role-based access controls, audit logging, secure development practices, and ongoing risk assessment under the HIPAA Security Rule.
4 · Subcontractors
We engage subcontractors only where necessary to perform our services, and we require each subcontractor that creates, receives, maintains, or transmits PHI on our behalf to sign a BAA imposing the same restrictions and conditions that apply to AIDAR.
5 · Breach notification
If we discover a breach of unsecured PHI, we will notify the covered provider without unreasonable delay and no later than the timelines required by the HIPAA Breach Notification Rule, with the information required to support the provider’s notification obligations.
6 · Individual rights
Patients’ rights under HIPAA, including the right to access, amend, and receive an accounting of disclosures of their PHI, are exercised through the covered healthcare provider. AIDAR will support the provider in responding to those requests within the timelines the law requires.
7 · Term and termination
Upon termination of the underlying agreement, AIDAR will return or destroy PHI as instructed by the covered provider, except as otherwise required by law. Where return or destruction is not feasible, we will extend the protections of the BAA to the retained PHI and limit further use to the purposes that make return or destruction infeasible.
8 · Complaints and contact
If you believe your PHI has been mishandled, you may file a complaint with the covered healthcare provider, with AIDAR at privacy@aidar.com, or with the U.S. Department of Health and Human Services, Office for Civil Rights. We will not retaliate for filing a complaint.