US compliance

HIPAA — technical safeguards for our US pilot partners.

Where Halo is deployed in a US healthcare context, we operate as a Business Associate under HIPAA. Technical safeguards under §164.312 are implemented; administrative and physical safeguards are documented in our BAA template.

HIPAA compliance badge

Our position, in detail

§164.312(a) — Access control

Unique user identification. Emergency access procedure. Automatic logoff. Encryption and decryption controls for PHI at rest.

§164.312(b) — Audit controls

Hardware, software, and procedural mechanisms record and examine activity in systems containing PHI. Immutable audit log in S3 Object Lock, 8-year retention.

§164.312(c) — Integrity

Mechanisms to authenticate that PHI has not been altered or destroyed in an unauthorised manner. Cryptographic hashing on every write, tamper detection on the audit log.

§164.312(d) — Person or entity authentication

MFA enforced for every user with access to PHI. SSO integration with customer IdPs supported. Machine identities scoped per-integration and rotated.

§164.312(e) — Transmission security

TLS 1.3 for all data in transit. Integrity controls for network payloads. Where email is the only channel, we send links to authenticated portal views rather than PHI in the message body.

Business Associate Agreement

Standard HHS-aligned BAA template available on request. Customer-drafted BAAs reviewed within 5 working days.

Breach notification

Breach notification to the covered entity without unreasonable delay and no later than 60 calendar days from discovery per §164.410.

Documents & evidence available under NDA

  • Statement of Applicability / Record of Processing / policy documents (as applicable to this framework)
  • Sub-processor register
  • Data Processing Agreement template
  • Incident response runbook (redacted)
  • Independent penetration test summary
  • Latest internal audit findings (redacted)

Need this evidence for procurement?

Send us an NDA and we’ll return the full evidence pack for HIPAA within 3 working days.