Compliance · HIPAA posture
ISOVERTIC HIPAA Operating Standard
Each row is an operating commitment ISOVERTIC signs before an engagement that touches protected health information. Send this page to your compliance officer. The BAA and the subcontractor list are available on request.
| Capability | ISOVERTIC operating standard |
|---|---|
| Business Associate Agreement | We sign a BAA before any engagement that touches PHI. Our template is available on request, and we review and execute client supplied BAAs. |
| Covered entity and business associate awareness | First week discovery identifies every PHI touchpoint, categorizes each system by exposure, and routes it to a compliant workflow. The output is a written data flow map your compliance lead signs off on. |
| Web tracking on patient facing pages | No Meta pixel, Google Analytics, or third party tracker on authenticated portals, scheduling flows, or any page that can reveal PHI, unless a BAA and written authorization exist. We follow the HHS OCR guidance on online tracking technologies as it stands after the June 2024 ruling in American Hospital Association v. Becerra, which vacated the part about unauthenticated pages and left the rest intact. |
| Server side event tracking | Where analytics is required on PHI adjacent pages we implement server side, PHI stripped event pipelines through a server container or a first party data layer, with the field list documented. |
| Ad platform data policies | We operate inside Meta's sensitive health information rules, Google's healthcare and medicines policy, and LinkedIn's advertising policies. We do not upload PHI derived audiences to any ad platform. |
| Retargeting on sensitive pages | Retargeting is off by default on symptom, diagnosis, treatment, and patient portal pages. Turning it on requires client sign off and a documented lawful basis. |
| Form data and lead intake | Lead forms on PHI adjacent flows route through HIPAA eligible infrastructure: BAA covered form delivery, encrypted at rest CRMs with BAAs, and HIPAA eligible email. No PHI in Google Sheets, Slack, or any CRM without a BAA. |
| Breach protocol | A documented incident response process with covered entity notification support inside the 60 day window the HHS Breach Notification Rule sets. |
| Workforce training | Every ISOVERTIC staff member and contractor who touches PHI completes annual HIPAA training and signs a confidentiality agreement. |
| Subcontractors | Every subcontractor with PHI access signs a downstream BAA. The subcontractor list is available to clients on request. |
ISOVERTIC · ISOVERTIC is an assumed name of Rocket Creative LLC. 600 Johnson Ave, Suite D5, Bohemia, NY 11716 · sale@isovertic.com · https://isovertic.com