Skip to content

HIPAA Compliance

Last updated: August 24, 2026

1. Our Commitment to HIPAA Compliance

Heyzl is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

As a platform connecting patients with healthcare providers across multiple countries, we understand the critical importance of maintaining the confidentiality, integrity, and availability of health information. We implement comprehensive administrative, physical, and technical safeguards to ensure HIPAA compliance across every layer of our infrastructure and operations.

2. What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that establishes national standards for protecting sensitive patient health information. HIPAA requires covered entities and their business associates to:

  • Ensure the confidentiality, integrity, and availability of PHI
  • Protect against reasonably anticipated threats to security
  • Protect against reasonably anticipated impermissible uses or disclosures
  • Ensure compliance by workforce members

3. Protected Health Information on the Platform

Protected Health Information (PHI) is any individually identifiable health information that is created, received, maintained, or transmitted by Heyzl. On our platform, PHI includes but is not limited to:

  • Medical records and health histories uploaded or shared with providers
  • Appointment and booking details, including procedure types and dates
  • Provider-patient messages exchanged through the platform messaging system
  • Telehealth video consultation recordings and session metadata
  • Billing and payment information associated with medical services
  • Insurance details and claims information
  • Lab results, imaging reports, and diagnostic documents
  • AI-generated medical record summaries and document analyses
  • Travel itineraries linked to medical procedures
  • Identity verification data collected during the progressive consent flow

Collection and processing of PHI is governed by our progressive consent flow. Health data features are controlled by server-side feature flags, are disabled by default, and are only activated after our HIPAA infrastructure is in place and you provide explicit, informed consent.

4. Our HIPAA Safeguards

Administrative Safeguards

  • Designated HIPAA Security Officer and Privacy Officer with documented roles and responsibilities
  • Comprehensive workforce training and security awareness programs conducted at onboarding and annually thereafter
  • Role-based access management and authorization procedures with least-privilege enforcement
  • Contingency planning, disaster recovery, and emergency mode operation procedures
  • Business Associate Agreements (BAAs) executed with all subprocessors and vendors handling PHI
  • Regular risk assessments and vulnerability analyses conducted at least annually
  • Documented security incident response procedures with escalation protocols
  • Sanctions policy for workforce members who violate HIPAA policies or procedures
  • Periodic review and update of all HIPAA policies in response to environmental or operational changes
  • Information system activity review with monthly audit log analysis

Physical Safeguards

  • SOC 2 Type II certified data centers with 24/7 physical monitoring and surveillance
  • Biometric and badge-based facility access controls with visitor management logs
  • Workstation security policies including screen lock enforcement and clean desk procedures
  • Full-disk encryption on all workstations and portable devices that may access PHI
  • Secure media disposal procedures including NIST 800-88 compliant data wiping and physical destruction
  • Facility access controls with validation procedures for maintenance and repair personnel
  • Environmental controls including fire suppression, climate control, and uninterruptible power supplies

Technical Safeguards

  • AES-256 encryption for all PHI at rest, including database fields, backups, and file storage
  • TLS 1.3 encryption for all data in transit between clients, servers, and third-party services
  • Multi-factor authentication (MFA) required for all user accounts and administrative access
  • Comprehensive audit logging and access tracking with tamper-evident log storage
  • Automatic session timeout after 15 minutes of inactivity with re-authentication required
  • Role-based access control (RBAC) ensuring users only access PHI necessary for their function
  • Data integrity controls including checksums, version control, and validation on all PHI modifications
  • Unique user identification — every account has a unique identifier; shared credentials are prohibited
  • Network segmentation isolating PHI-containing systems from general application infrastructure
  • Intrusion detection and prevention systems (IDS/IPS) monitoring for unauthorized access attempts
  • Automated vulnerability scanning and penetration testing on a quarterly basis
  • Encryption key management with hardware security modules (HSMs) and regular key rotation

5. Minimum Necessary Standard

Heyzl adheres to the HIPAA Minimum Necessary Standard, which requires that we limit the use, disclosure, and request of PHI to the minimum amount necessary to accomplish the intended purpose. In practice, this means:

  • Role-based access controls: Each workforce member and system component is granted access only to the specific PHI required for their job function. For example, billing staff can access payment-related PHI but not clinical records.
  • Scoped API permissions: Internal services and third-party integrations request and receive only the data fields they need. Our API layer enforces field-level filtering on all PHI responses.
  • Provider-specific data views: Healthcare providers on the platform can only view PHI for patients who have actively shared information with them or booked their services.
  • AI processing boundaries: Our AI chatbot, document analysis, and medical record summarization features process only the specific documents or data submitted by the user for that purpose, and do not access the user's broader medical record store.
  • Support access controls: Customer support staff access PHI only when necessary to resolve a specific issue, with all access logged and subject to audit review.
  • Time-limited access: Temporary access grants for operational needs expire automatically and are reviewed by the Security Officer.

The Minimum Necessary Standard does not apply to disclosures made to a healthcare provider for treatment purposes, disclosures made to you about your own PHI, or disclosures authorized by you.

6. De-Identification of Health Information

Heyzl uses de-identified health information for analytics, platform improvement, and AI model training. De-identified data is not considered PHI and is not subject to HIPAA restrictions. We employ the following de-identification methods:

Safe Harbor Method

We remove all 18 categories of identifiers specified by the HIPAA Safe Harbor method, including:

  • Names and initials
  • Geographic data smaller than state
  • Dates (except year) related to an individual
  • Phone and fax numbers
  • Email addresses
  • Social Security numbers
  • Medical record numbers
  • Health plan beneficiary numbers
  • Account numbers
  • Certificate/license numbers
  • Vehicle identifiers and serial numbers
  • Device identifiers and serial numbers
  • Web URLs and IP addresses
  • Biometric identifiers
  • Full-face photographs
  • Any other unique identifying number

How We Use De-Identified Data

  • Improving AI features such as our chatbot, document analysis, and medical record summarization — models are trained only on de-identified data
  • Aggregate analytics on provider quality, procedure outcomes, and platform usage patterns
  • Research to improve medical tourism safety and patient outcomes
  • Error monitoring and debugging via Sentry (PHI is stripped before transmission)

7. Your HIPAA Rights

Under HIPAA, you have the following rights regarding your Protected Health Information. You may exercise any of these rights by visiting the Privacy & Health Data section of your account dashboard or by contacting our Privacy Officer.

Right to Access

You have the right to access and obtain a copy of your medical records and health information maintained by MedScovery. You can request your records through the Privacy & Health Data section of your account dashboard. We will respond to your request within 30 days. If we need additional time, we will notify you of the extension (up to an additional 30 days) and the reason for the delay.

Right to Amend

You can request corrections to your health information if you believe it is inaccurate or incomplete. Submit amendment requests through your account dashboard or by contacting our Privacy Officer. We will respond within 60 days. If we deny your request, we will provide a written explanation and inform you of your right to submit a statement of disagreement.

Right to Request Restrictions

You can request restrictions on how we use or disclose your health information for treatment, payment, or healthcare operations. You may also restrict disclosures to your health plan for services you paid for in full out of pocket. Submit restriction requests through your account settings or by contacting our Privacy Officer. We are not required to agree to all restrictions, but if we do, we are bound by them.

Right to Confidential Communications

You can request that we communicate with you about health matters in a specific way or at a specific location. For example, you may request that we only contact you via encrypted email or at a particular phone number. Update your communication preferences in your account dashboard under Notification Settings.

Right to an Accounting of Disclosures

You have the right to receive a list of instances where we disclosed your health information for purposes other than treatment, payment, or healthcare operations. You may request an accounting of disclosures for up to six years prior to your request. The first accounting in any 12-month period is free; additional requests may be subject to a reasonable fee.

Right to File a Complaint

You can file a complaint if you believe your privacy rights have been violated. File a complaint directly with our Privacy Officer through the platform or submit a complaint to the U.S. Department of Health and Human Services Office for Civil Rights. We will not retaliate against you for filing a complaint.

8. Breach Notification

In the unlikely event of a breach of unsecured PHI, Heyzl will follow the HIPAA Breach Notification Rule and applicable state breach notification laws:

Notification Timelines

  • Individual notice (60 days): We will notify affected individuals without unreasonable delay, and in no case later than 60 calendar days after discovery of the breach, via email or first-class mail.
  • HHS notification: We will notify the Secretary of Health and Human Services. For breaches affecting 500 or more individuals, notification occurs within 60 days. For smaller breaches, notification is provided annually.
  • Media notification: If the breach affects more than 500 residents of a single state or jurisdiction, we will notify prominent media outlets in that state within 60 days.
  • State Attorney General notification: Where required by state law, we will notify the applicable state Attorney General within the timeframe specified by that state's breach notification statute.

What Our Notification Will Include

  • A description of the breach, including the date(s) of the breach and date of discovery
  • The types of PHI involved (e.g., name, diagnosis, treatment information, financial data)
  • Steps you should take to protect yourself from potential harm
  • What we are doing to investigate the breach, mitigate harm, and prevent future occurrences
  • Contact information for our Privacy Officer and the HHS Office for Civil Rights

9. Business Associate Agreements

We enter into Business Associate Agreements (BAAs) with all third-party service providers who create, receive, maintain, or transmit PHI on our behalf. These agreements contractually require our partners to implement appropriate safeguards for PHI, report security incidents and breaches, and comply with applicable HIPAA requirements.

The following is a summary of our key Business Associates and the role each plays in processing PHI:

Supabase

Role: Authentication, database hosting, and real-time data infrastructure

PHI involved: User accounts, encrypted medical records, appointment data, and provider-patient communications

Stripe

Role: Payment processing and escrow protection via Stripe Connect

PHI involved: Billing information, transaction records, and payment details associated with medical services

Twilio

Role: Video consultations, SMS notifications, and secure messaging

PHI involved: Telehealth session data, appointment reminders, and communication logs

Persona

Role: Identity verification for patients and healthcare providers

PHI involved: Identity documents, verification results, and associated personal identifiers

Sentry

Role: Error monitoring and application performance

PHI involved: Sentry is configured to strip and redact all PHI before transmission; only de-identified error metadata is processed

We regularly review and update our BAAs to ensure they reflect current data processing activities. If a Business Associate fails to meet its obligations, we take immediate corrective action, including termination of the agreement if necessary.

10. Employee Training

All Heyzl workforce members — including employees, contractors, and temporary staff — are required to complete HIPAA compliance training as a condition of their access to PHI and platform systems.

  • New hire training: All workforce members complete HIPAA training within their first week, before being granted access to any systems containing PHI
  • Annual refresher training: Comprehensive training is conducted annually, covering updates to HIPAA regulations, company policies, and emerging threats
  • Role-specific training: Additional training modules for roles with elevated PHI access, including engineering, customer support, and clinical operations teams
  • Incident response drills: Regular tabletop exercises simulating breach scenarios to ensure the team can respond quickly and correctly
  • Phishing and social engineering awareness: Ongoing simulated phishing campaigns and security awareness education
  • Training verification: Completion records are maintained for a minimum of six years and are subject to audit review
  • Policy acknowledgment: All workforce members must sign an acknowledgment of HIPAA policies and understand the sanctions for violations

11. Questions About HIPAA Compliance?

If you have questions about our HIPAA compliance practices, wish to exercise your privacy rights, or need to report a potential security concern, please contact us:

Contact Legal Team

You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint.