Effective Date: December 23, 2024 | Last Updated: December 23, 2024
Commitment to Healthcare Privacy. The Bridge Placement Network Inc. ("The Bridge," "Company," "we," "us," or "our") is committed to protecting the privacy and security of Protected Health Information ("PHI") in accordance with the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations ("HIPAA"), including the HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164), the HIPAA Security Rule (45 CFR Part 160 and Subparts A and C of Part 164), and the HITECH Act.
When The Bridge provides services that involve the creation, receipt, maintenance, or transmission of PHI on behalf of a Covered Entity (as defined under HIPAA), The Bridge functions as a "Business Associate" within the meaning of 45 CFR § 160.103. In such capacity, we are bound by the applicable provisions of HIPAA as set forth in Business Associate Agreements ("BAAs") executed with Covered Entities utilizing our Platform for patient placement and care coordination services.
This HIPAA Compliance Statement applies to all PHI that The Bridge creates, receives, maintains, or transmits in connection with its services. This statement is supplemental to, and does not supersede, our Privacy Policy and Terms of Service, which govern the collection and use of all personal information processed through our Platform.
IMPORTANT NOTICE: HIPAA obligations apply only when The Bridge is acting as a Business Associate to a Covered Entity under an executed BAA. Information provided directly to The Bridge by individuals for their own use (such as families conducting independent searches) may not be subject to HIPAA protections unless such information constitutes PHI received from or maintained on behalf of a Covered Entity. The Bridge's HIPAA compliance obligations do not extend to activities outside the scope of an applicable BAA.
Protected Health Information, as defined by 45 CFR § 160.103, refers to individually identifiable health information that is: (a) transmitted by or maintained in electronic media; (b) transmitted or maintained in any other form or medium; (c) created or received by a healthcare provider, health plan, public health authority, employer, life insurer, school or university, or healthcare clearinghouse; and (d) relates to the past, present, or future physical or mental health condition of an individual, the provision of healthcare to an individual, or the past, present, or future payment for the provision of healthcare to an individual.
In the course of providing services, The Bridge may process the following categories of PHI:
The Bridge maintains a comprehensive security program implementing the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR §§ 164.302-164.318).
Designated Security and Privacy Officers; documented security policies and procedures; formal risk analysis and management program
Background checks; role-based access authorization; termination procedures; regular HIPAA training and awareness programs
Least-privilege access principles; formal access authorization procedures; documented policies for access establishment, modification, and termination
Incident identification, response, and documentation procedures; established escalation protocols; post-incident analysis and remediation
Prior to receiving, creating, or maintaining PHI from a Covered Entity, The Bridge requires the execution of a Business Associate Agreement that satisfies the requirements of 45 CFR § 164.504(e). Our standard BAA addresses all required elements, including permissible uses and disclosures, safeguarding requirements, subcontractor obligations, breach notification, and termination provisions.
In accordance with 45 CFR § 164.502(e)(1)(ii) and 45 CFR § 164.504(e)(2)(ii)(D), The Bridge requires all subcontractors that create, receive, maintain, or transmit PHI on our behalf to execute Business Associate Agreements containing substantially similar terms and conditions.
Organizations requiring a BAA to use The Bridge Platform should contact our Compliance Department at compliance@thebridge.care. We can provide our standard BAA template or review organization-specific agreements.
In compliance with 45 CFR § 164.502(b) and 45 CFR § 164.514(d), The Bridge adheres to the "minimum necessary" standard. We make reasonable efforts to limit the use, disclosure, and request of PHI to the minimum amount necessary to accomplish the intended purpose. Our Platform is designed with role-based access controls and data minimization principles to limit PHI exposure to only what is required for authorized purposes.
A "Breach" is defined in accordance with 45 CFR § 164.402 as the acquisition, access, use, or disclosure of PHI in a manner not permitted by the HIPAA Privacy Rule that compromises the security or privacy of the PHI, unless an exception applies or a risk assessment demonstrates low probability of compromise.
In the event of a Breach of unsecured PHI, The Bridge will:
The Bridge will cooperate with Covered Entities in breach investigations, notifications to affected individuals, and notifications to the Department of Health and Human Services as required by 45 CFR §§ 164.404-164.410.
The Bridge supports Covered Entities in fulfilling individuals' rights under HIPAA, including:
The Bridge maintains an ongoing compliance program including: periodic risk assessments; internal and external security audits; penetration testing; employee training; policy review and updates; and engagement with qualified healthcare compliance consultants. Documentation of compliance activities is maintained and available for review by BAA partners upon request.
DISCLAIMER: While The Bridge is committed to HIPAA compliance and implements comprehensive safeguards, this HIPAA Compliance Statement is provided for informational purposes only and does not constitute legal advice. The Bridge's liability for any breach of its HIPAA obligations shall be governed solely by the terms of the applicable Business Associate Agreement. Nothing in this Statement shall be construed to create obligations beyond those required by HIPAA and applicable BAAs or to create any private right of action not provided by law.
For HIPAA-related inquiries, BAA requests, compliance questions, or to report a potential security incident:
HIPAA Privacy and Security Officer
The Bridge Placement Network Inc.
Email: compliance@thebridge.care
Security Incident Hotline: [Phone Number]
Address: [Your Business Address]
Regulatory Reference: This HIPAA Compliance Statement reflects The Bridge's commitment to compliance with the Health Insurance Portability and Accountability Act of 1996 (Pub. L. 104-191), the HITECH Act (Title XIII of Division A and Title IV of Division B of the American Recovery and Reinvestment Act of 2009, Pub. L. 111-5), and the HIPAA Final Omnibus Rule (78 FR 5566). For authoritative guidance, please consult the regulations published by the U.S. Department of Health and Human Services.