Is SurgeryHub HIPAA compliant?
We do not use that phrase. HIPAA compliance is a program a covered entity runs for protected health information, not a label that comes with a website (U.S. Department of Health and Human Services [HHS], n.d.-a). The pain center or surgery center is the covered entity. They treat people. The packet is theirs.
SurgeryHub hosts public pages: hours, services, who is on staff, an accreditation mark. A name on a door plus “we do knee injections” is not, by itself, a patient’s designated record set. A name plus last meal time, allergies, and a signature on our disk would be protected health information if we kept it (45 C.F.R. § 160.103). We are built so that packet never sits on our computers. That is a design choice. It is not a government certification.
Talk to an attorney who does health privacy, not only a general business lawyer, before you rely on this for a survey or a payer audit.
