Compliance
HIPAA Compliance
How Data Soft Logic protects patient health information as your Business Associate — safeguards, audit trails, breach notification, and shared responsibilities.
Last updated: September 16, 2026
1. Our role under HIPAA
When your agency uses a Data Soft Logic product to create, receive, store, or transmit protected health information (PHI), your agency is the Covered Entity and DSL acts as a Business Associate. We sign a Business Associate Agreement (BAA) with every customer before PHI is placed in the system.
The BAA defines the permitted uses of PHI, our safeguards, breach-notification duties, subcontractor obligations, and what happens to your data when the agreement ends.
2. Administrative safeguards
- Written security policies reviewed on a regular cycle.
- Workforce training on privacy and security, with sanctions for violations.
- Role-based access so staff only reach the records their job requires.
- Access reviews when staff join, change roles, or leave.
- Documented incident response and breach-notification procedures.
- Vendor review and signed agreements with subcontractors that touch PHI.
3. Technical safeguards
- Encryption of PHI in transit using TLS, and encryption at rest in our hosting environment.
- Unique user accounts with password requirements and automatic session timeout.
- Audit logging of record access and changes, retained for investigation and survey support.
- Input validation and application hardening to block injection and scripting attempts.
- Backups with tested restore procedures and disaster-recovery planning.
- Continuous monitoring for unusual access patterns and failed-login activity.
4. Physical safeguards
DSL systems are hosted in data centers with controlled physical access, environmental protection, redundant power, and 24/7 monitoring. DSL staff do not store PHI on local workstations or removable media.
5. Minimum necessary and access control
The platform enforces the minimum-necessary principle through role-based permissions: clinicians, schedulers, QA reviewers, and billing staff each see the information their role requires. Agency administrators control those roles and can review who has access at any time.
6. Audit trails and survey readiness
Every record view, edit, and signature is logged with user, timestamp, and action. Agencies can produce these trails during internal audits, payer reviews, and accreditation surveys. Documentation, orders, and visit notes retain their version history so you can show what was recorded and when.
7. Breach notification
If DSL discovers a breach of unsecured PHI, we investigate promptly, contain the incident, and notify affected agencies without unreasonable delay and within the timeframes required by the HIPAA Breach Notification Rule and your BAA. Notifications include what happened, the information involved, our response, and recommended next steps.
8. What remains your agency's responsibility
- Assigning and reviewing user roles, and deactivating accounts when staff depart.
- Training your workforce on privacy practices and your own policies.
- Protecting devices, networks, and printed output at your locations.
- Responding to patient requests for access, amendment, and accounting of disclosures.
- Maintaining your own risk analysis and contingency plan as required by the Security Rule.
9. Important disclaimer
DSL software supports your compliance program; it does not replace it. Using DSL does not by itself make an agency HIPAA compliant, and DSL does not guarantee accreditation, survey success, or regulatory outcomes. Compliance is a shared responsibility between your agency and its technology vendors.
10. Request a BAA or security documentation
Compliance officers can request a copy of our Business Associate Agreement or a security overview for vendor review by emailing sales@datasoftlogic.com or calling 866.430.0263.
Questions about this policy?
Our team can walk your compliance officer or legal counsel through how DSL handles your agency's data.