Security & compliance
Security & compliance
Healthcare organizations trust ZUHTA with sensitive information. This page explains how we approach that responsibility and states only what we can support.
How we approach protected health information
Access matched to the job
People see only the systems and records their role requires, and you approve that access.
Written agreements first
Before ZUHTA handles protected health information, each side’s responsibilities are set out in writing, including a business associate agreement where HIPAA requires one.
Trained people
Everyone who works on your account is trained on privacy and security requirements before they start.
A record of activity
Work in your systems is traceable, so you can see who did what.
Shared responsibility
HIPAA places obligations on both covered entities and their business associates. ZUHTA takes on the responsibilities that belong to a business associate. Your organization keeps the responsibilities that belong to a covered entity. We walk through that split with you during onboarding.
Certifications and attestations
Independent certifications and assessments will be listed here once they are completed and verifiable.
Questions about security?
Ask us during your consultation. We will answer plainly.
