At SimpleSpa we are dedicated to the six best security practices for the protection of electronic protected health information (ePHI) and credit card data, which include, but are not limited to:
- Maintaining a secure network
- Encrypting and protecting ePHI and cardholder data
- Maintaining a Vulnerability Management and Assessment Program
- Implementing strong access control measures
- Monitoring and testing production and development networks
- Maintaining a thorough internal information security program and policies
SimpleSpa supports customers who are subject to the requirements of the Health Insurance Portability and Accountability Act (HIPAA). Under HIPAA, certain information about a person’s health or health care services is classified as Protected Health Information (PHI). If You are subject to HIPAA and wish to use Our Services with PHI, it is Your responsibility to request a Business Associate Agreement (“BAA”) with SimpleSpa. You are solely responsible for determining whether You are subject to HIPAA requirements. If You are subject to HIPAA and have not entered into a BAA, You must not use any of Our digital properties in connection with PHI. You agree to indemnify, defend, and hold harmless SimpleSpa and its directors, employees, and affiliates against any claim relating to a failure by You to request a BAA with SimpleSpa.