HIPAA Compliance
Last updated: May 28, 2026
CliniqHQ is designed to help clinics manage protected health information (PHI) with strong security and privacy controls. This page describes our HIPAA-aligned practices. Clinics subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) may require a Business Associate Agreement (BAA) before using CliniqHQ with PHI — contact legal@cliniqhq.com.
1. Our role
In HIPAA terms, healthcare clinics and providers are typically Covered Entities or their workforce when they enter patient data. CliniqHQ generally acts as a Business Associate when we create, receive, maintain, or transmit PHI on behalf of a clinic through the Services.
2. Administrative safeguards
- Security and privacy policies governing access to production systems
- Role-based access control with least-privilege principles for staff accounts
- Workforce confidentiality obligations
- Incident response procedures for suspected data breaches
- Regular review of access logs and administrative actions
3. Technical safeguards
- Encryption in transit using TLS for all web and API communication
- Encryption at rest for sensitive credentials and infrastructure-managed storage
- Unique user authentication with secure password hashing
- Multi-tenant logical isolation so each clinic's data is separated
- Audit logging of key system and user actions
- Automatic session expiration and token-based authentication
4. Physical safeguards
CliniqHQ is hosted on enterprise cloud infrastructure (Google Cloud) with physical access controls, environmental protections, and compliance certifications managed by the cloud provider.
5. Data use limitations
We use PHI only to provide, maintain, and improve the Services as instructed by the clinic, including:
- Appointment scheduling and reminders
- Electronic health records and prescriptions
- Billing and clinic operations
- Optional integrations authorized by the clinic (e.g., Google Calendar sync of appointment events)
We do not use PHI for advertising or sell PHI to third parties.
6. Subprocessors
We use vetted subprocessors (such as cloud hosting, email, SMS, and AI providers) under agreements that require appropriate data protection. A list is available on request at privacy@cliniqhq.com.
7. Breach notification
If we become aware of a breach of unsecured PHI in our systems, we will notify affected clinics without unreasonable delay and in accordance with applicable law and any executed BAA.
8. Clinic obligations
Clinics using CliniqHQ with PHI must:
- Ensure they have a lawful basis and appropriate patient authorizations
- Assign appropriate roles and permissions to staff
- Use strong passwords and protect login credentials
- Report suspected unauthorized access promptly
- Configure optional integrations in compliance with their policies
9. International clinics
Clinics outside the United States may be subject to local health data laws (such as India's Digital Personal Data Protection Act or state-level regulations). CliniqHQ's security controls support compliance efforts, but each clinic remains responsible for its regulatory obligations.
10. Contact
For HIPAA or BAA inquiries:
legal@cliniqhq.com