This Acceptable Use Policy (“AUP”) forms part of the HIPAAWorks Terms of Service. Capitalized terms not defined here have the meaning given in the Terms.
1. Authorized business use
Customer and its users may use HIPAAWorks only for lawful internal business purposes related to Customer's organization-level security self-assessment, remediation planning, and documentation.
The Service must not be used as:
- a patient portal or personal health record;
- an electronic health record, practice-management, billing, claims, or clinical system;
- a repository for patient records;
- an emergency, clinical-decision, diagnosis, or treatment service; or
- a substitute for legal, regulatory, security, or other professional advice.
2. Prohibited patient information and PHI
Do not submit protected health information, patient information, or patient-level health data anywhere in the Service.
Prohibited content includes:
- patient names, initials, faces, voices, contact information, or addresses;
- dates associated with a patient, except a year when legally permitted and properly de-identified;
- medical-record, account, certificate, insurance, device, or other identifiers;
- diagnoses, treatment, prescriptions, test results, appointment information, or billing details linked to a person;
- photographs or screenshots showing patients, charts, labels, schedules, monitors, portals, messages, or records;
- files exported from an EHR, billing, imaging, laboratory, pharmacy, or patient communication system; and
- any information that Customer treats or is required to treat as PHI.
Before uploading a photo or document, inspect and redact it. Pay particular attention to screens, papers, whiteboards, reflections, labels, sign-in areas, and people in the background.
Do not include prohibited information in comments, risk-acceptance notes, vendor descriptions, organization profiles, support requests, filenames, or feedback.
3. Security and access restrictions
Users must not:
- access or attempt to access another organization's data;
- share accounts or authentication factors;
- bypass role, subscription, rate, storage, or access controls;
- probe, scan, test, or exploit the Service without our prior written authorization;
- introduce malware, malicious code, or content designed to interfere with the Service;
- attempt to obtain credentials, tokens, signed links, or secrets belonging to another person;
- use automated requests in a way that burdens or disrupts the Service; or
- conceal the source of abusive traffic.
Good-faith security research must be coordinated through [email protected].
4. Unlawful, harmful, and infringing content
Users must not submit or use the Service for content or conduct that:
- violates law or another person's rights;
- is fraudulent, deceptive, defamatory, harassing, threatening, or discriminatory;
- infringes intellectual property, privacy, publicity, or confidentiality rights;
- contains unlawful personal data, credentials, secrets, or confidential information the user is not authorized to provide;
- facilitates unlawful surveillance, unauthorized access, or cyberattack;
- misrepresents HIPAAWorks output as an independent audit, certification, legal opinion, or regulatory approval; or
- falsely claims that a finding, safeguard, document, or vendor was independently verified.
5. AI and generated content
Users must not:
- place PHI, secrets, or unnecessary personal information in content that may be processed by AI;
- use prompt-injection or similar content to override system restrictions or obtain another customer's information;
- represent AI-generated guidance as professional advice or an independent determination; or
- publish generated content without appropriate human review.
6. Enforcement
We may remove or restrict access to content, suspend a user or feature, or suspend or terminate an account when we reasonably believe a violation has occurred or action is necessary to protect people, data, or the Service.
When practical, we will provide notice and an opportunity to cure. We may act immediately for suspected PHI, security threats, illegal content, or material risk.
7. Reporting
Report suspected violations to [email protected]. Do not include PHI, credentials, evidence contents, or other sensitive content in the report. Provide only the minimum information needed to identify the affected account or item.