Privacy before access

Business conversation first. Protected data only inside the right agreement and system.

SmartMBX does not treat a marketing form, public chatbot or ordinary email as a place for patient information.

Our operating boundary

BAA before PHI.

When SmartMBX acts as a business associate for work involving PHI, the parties first define permitted work, access, safeguards and responsibilities in a written agreement.

01

Public website

Business contact and workflow information only. No patient identifiers.

No PHI
02

Scoping

Identify the service, systems, people, minimum necessary access and data flow.

Define
03

Agreement

Put the applicable service agreement and BAA in place before protected data moves.

Authorize
04

Approved environment

Use the agreed administrative, physical and technical safeguards, access controls and audit process.

Protect
Official guidance

What the rule requires depends on the relationship.

HHS explains that covered entities and business associates are subject to HIPAA requirements based on their role, and that a covered entity engaging a business associate for work involving PHI needs a written business associate contract or arrangement. HHS also describes the Security Rule as requiring reasonable and appropriate administrative, physical and technical safeguards for ePHI.

Business associate agreements

The agreement describes permitted and required uses and disclosures and the safeguards and responsibilities that apply.

HHS guidance →

Minimum necessary

Access and use should be limited to what is reasonably necessary for the intended purpose, subject to applicable exceptions and the actual relationship.

HHS guidance →

This page is an operating summary, not a legal opinion or certification. The HIPAA Rules, signed agreements and qualified legal/security guidance control.