HIPAAWorks is a product of Passing Lanes Solutions LLC (“HIPAAWorks,” “we,” “us,” or “our”). This Privacy Notice explains how we collect, use, disclose, and retain information through hipaaworks.com, app.hipaaworks.com, and related HIPAAWorks services (collectively, the “Service”).
1. Scope and roles
HIPAAWorks is a business-to-business service for healthcare practices and their authorized workforce members. It is not a patient portal or personal health record.
For account administration, billing, security, communications, product operations, and our own legal obligations, Passing Lanes Solutions LLC generally determines why and how personal data is processed.
For personal data a customer organization submits and instructs us to process within its workspace (“Customer Content”), the customer generally determines the business purpose, and we process the information to provide the Service. Our Data Processing Addendum provides additional terms when applicable.
If you use HIPAAWorks through your employer or another organization, that organization controls your workspace, role, and Customer Content. Direct questions about the organization's use of your information to the organization.
2. HIPAA and patient information
The Service is designed to process information about an organization's security program, technology, vendors, and remediation work—not patient records.
Do not submit protected health information (“PHI”), patient information, or patient-level health data to HIPAAWorks. This prohibition applies to all fields, filenames, comments, support messages, photographs, screenshots, PDFs, and other uploads.
HIPAAWorks does not intend to create, receive, maintain, transmit, or access PHI on behalf of a covered entity, and the current Service is not offered under a Business Associate Agreement.
If you believe patient information has been submitted, contact [email protected] promptly without including the patient information in your message. We may restrict, quarantine, or delete suspected prohibited content and will evaluate the matter under applicable law.
Information about a healthcare practice's security posture can be highly sensitive even when it is not PHI. We treat that information as confidential Customer Content as described in our Terms and DPA.
3. Information we collect
3.1 Account and identity information
We and our identity provider may collect:
- name;
- email address;
- user and session identifiers;
- organization membership and role;
- authentication method and authentication-security status;
- invitation email, inviter, invitation status, and expiration;
- profile image or other identity-provider information if made available; and
- sign-in, device, browser, IP address, and security-event information.
If you choose Google or Microsoft sign-in, the selected provider and our authentication provider process information needed to authenticate you.
3.2 Organization and business-contact information
We collect information such as:
- organization and legal-entity name;
- organization type, size, state, and website;
- privacy and security officer names, roles, and related governance contacts;
- policy-approver role;
- workforce composition and organization settings; and
- names, email addresses, roles, and invitations for authorized users.
3.3 Technology, environment, and vendor information
We collect organization-provided information about:
- EHR, email, productivity, billing, telehealth, communications, backup, file storage, and remote-access platforms;
- devices, servers, networks, Wi-Fi, office locations, fax, imaging equipment, external connections, and physical environment;
- whether systems or devices handle patient information, without requesting the patient information itself;
- IT support arrangements;
- vendor and MSP names, types, and descriptions of what they handle; and
- governance, policy, insurance, and workforce facts.
3.4 Assessment and remediation information
We collect:
- Quick Check and assessment answers;
- assessment progress, completion dates, and control-set version;
- deterministically derived findings, status, and assigned severity;
- remediation status, dates, and activity;
- risk-acceptance rationales and optional notes;
- gap comments;
- user feedback about guidance; and
- user identity snapshots associated with recorded activity, which may include name and email.
These records reflect organization-provided information. They are not independently verified by HIPAAWorks.
3.5 Uploaded evidence and generated documents
Paid features may allow authorized users to upload photographs and PDFs that document physical or administrative safeguards. We collect the file, filename, content type, size, upload date, storage location, uploader context, and any link to an identified gap.
We also create and store organization-requested reports containing organization, assessment, finding, vendor, and remediation information. Generated reports are currently retained as dated, append-only records and may be superseded by later reports rather than overwritten.
Do not upload patient information. Review and redact documents and photographs before upload.
3.6 Subscription and transaction information
We collect:
- selected plan and billing interval;
- subscription status and entitlement dates;
- a HIPAAWorks organization identifier passed to Stripe as transaction metadata;
- Stripe customer and subscription identifiers;
- checkout, promotion, plan-change, and cancellation status; and
- limited transaction metadata returned by Stripe.
Stripe processes complete payment-card and payment-method details through its hosted interfaces. The implemented HIPAAWorks checkout flow does not send complete card details to HIPAAWorks application servers.
3.7 Communications and support
We collect information you provide in:
- support, privacy, security, and legal inquiries;
- beta feedback;
- organization invitations; and
- other communications with us.
Do not include PHI, passwords, secret keys, or uploaded evidence in email or support messages.
3.8 Usage, analytics, and diagnostics
The current application sends server-authored operational events to PostHog. These events may include:
- a pseudonymous organization identifier;
- onboarding step;
- selected subscription tier and subscription-event status;
- assessment completion and counts;
- report views or exports;
- remediation-status category;
- feedback rating; and
- whether certain organization-profile sections were updated.
The current application does not use PostHog browser autocapture or session replay and does not send assessment free text, evidence contents, or detailed gap information to PostHog.
Sentry may receive error and diagnostic information from production browser, server, and edge environments. Current configuration disables session replay and performance tracing, disables default PII collection, and removes request bodies, cookies, and headers before sending an event. An event may still include error type, application code location, request URL, hostname, time, runtime information, and coarse diagnostic tags.
We and our hosting, network, authentication, and security providers may also process standard server data such as IP address, user agent, request time, requested URL, and security signals.
3.9 Public website information
If an authorized user provides an organization website, a profile-summary feature may retrieve publicly available text from that website and combine it with the organization's profile for AI-assisted summarization. The feature may process the website URL, public page text, and resulting summary.
4. How we use information
We use information to:
- create and secure accounts and organization workspaces;
- authenticate users and enforce roles;
- provide onboarding, Quick Check, assessments, findings, guidance, comments, evidence storage, reports, and reassessment features;
- administer subscriptions and plan entitlements;
- provide transactional notices and organization invitations;
- operate, maintain, troubleshoot, and secure the Service;
- detect abuse, fraud, prohibited data, and unauthorized access;
- measure feature operation and product adoption using minimized analytics;
- generate AI-assisted summaries, remediation guidance, and report narrative;
- respond to support, legal, privacy, and security requests;
- enforce our agreements and protect rights and safety;
- comply with law; and
- develop and improve the Service using information that is appropriately minimized, aggregated, or de-identified.
We do not use Customer Content to make clinical decisions, determine a patient's eligibility, or provide patient care.
5. Artificial intelligence processing
We use Anthropic's Claude models for limited drafting functions.
Remediation guidance
Depending on the identified gap, Anthropic may receive:
- allowlisted technology-profile values, including named platforms and, in some cases, a vendor name;
- control title, category, and description;
- fixed severity and finding status;
- question text; and
- closed-set assessment answers.
This path is designed to exclude organization ID, user ID, uploaded evidence, risk-acceptance notes, comments, and assessment free-text answers.
Report narrative
Anthropic may receive:
- organization name;
- selected organization and technology-profile facts;
- vendor names;
- assessment and report dates;
- control-set version;
- aggregate coverage, finding, severity, and remediation-status counts; and
- control titles and safeguard categories associated with findings.
Organization profile summary
Anthropic may receive:
- organization name, type, size, state, website, and public website text;
- technology and environment facts;
- governance contact names and roles;
- vendor names and descriptions; and
- other profile details included in the summary context.
AI limitations
The application uses deterministic rules—not AI—to assign control severity, derive final finding status, and record remediation-state changes. AI-generated text is suggested content and may be inaccurate or incomplete. Authorized users must review it.
Do not include PHI, patient information, secrets, or unnecessary personal data in information that may be processed by AI.
We access Anthropic's Claude models through Amazon Bedrock. Amazon Bedrock does not use Customer Content to train its models and does not retain it beyond what is necessary to process the request.
6. How we disclose information
We may disclose information as follows.
6.1 Customer-authorized users
Information in an organization workspace is available according to the user's role. Viewers may see organization information and Customer Content that their role permits. Owners and administrators can manage membership and may see user identity and invitation information.
6.2 Service providers
We disclose information to providers that help operate the Service, including:
- Vercel for application hosting and server execution;
- Supabase for database and private object storage;
- Clerk for authentication, user identity, and sessions;
- Stripe for checkout, payments, subscriptions, and billing management;
- Anthropic for the AI functions described above;
- PostHog for minimized server-side product analytics;
- Sentry for error monitoring;
- Resend for transactional email;
- Cloudflare for website delivery, DNS, network security, and temporary pre-launch access controls; and
- Google or Microsoft when a user selects those identity providers.
The list above reflects our current subprocessors. Contact [email protected] for the current subprocessor list or advance notice of a new subprocessor.
6.3 Legal, security, and safety disclosures
We may disclose information when we reasonably believe disclosure is necessary to:
- comply with law, legal process, or a binding government request;
- protect the rights, safety, or security of HIPAAWorks, customers, users, or the public;
- investigate fraud, abuse, unauthorized access, or a security incident; or
- establish, exercise, or defend legal claims.
When permitted, we will seek to notify the affected customer and limit disclosure to what is required.
6.4 Corporate transactions
Information may be disclosed in connection with a financing, merger, reorganization, acquisition, sale of assets, or similar transaction, subject to appropriate confidentiality protections. Any successor remains subject to applicable legal and contractual obligations.
6.5 No sale or targeted advertising
Under the verified current configuration, we do not sell personal data, share it for cross-context behavioral advertising, or use Customer Content for targeted advertising. We will not do so without the customer's explicit written consent.
7. Cookies and similar technologies
The Service may use cookies or similar browser storage that are necessary for authentication, security, session management, preferences, and fraud prevention. Clerk and Cloudflare may set or process security and authentication cookies. Stripe uses its own technologies on Stripe-hosted checkout and billing pages.
The current HIPAAWorks application does not use browser-based PostHog autocapture, advertising pixels, or session replay. If we later introduce nonessential analytics or advertising technologies, we will update this Notice and provide any choices required by law.
Browser controls may block cookies, but blocking necessary cookies can prevent sign-in or other Service functions.
8. Retention and deletion
We retain information for the period reasonably necessary to provide and secure the Service, maintain organization-requested records, comply with law, resolve disputes, and enforce agreements.
Current product behavior includes different retention characteristics:
- editable organization and profile data remains while the workspace is active;
- incomplete assessment data may be updated or removed through product workflows;
- completed assessment answers and related finding history are designed as historical organization-attested records;
- remediation activity and comments are append-only;
- customer-uploaded evidence may currently be deleted by authorized users;
- generated reports are stored as dated, append-only artifacts and may be superseded rather than deleted;
- billing, security, consent, and legal records may be retained separately; and
- residual copies may remain temporarily in backups after deletion from active systems.
Upon a written request and cancellation of the subscription, we will delete the organization's data from the Service.
We do not rely on an ordinary retention schedule as a reason to retain prohibited PHI.
9. Security
We use administrative, technical, and organizational safeguards designed for the nature of the information we process. Current safeguards include authenticated access, organization-based tenant isolation, role controls, private object storage, short-lived signed file links, server-side subscription enforcement, request-data scrubbing for monitoring, and minimized analytics and AI inputs.
No method of transmission or storage is completely secure. We cannot guarantee that unauthorized access, loss, or misuse will never occur.
Users should use supported MFA or secured SSO, assign least-privilege roles, remove former users promptly, and protect exported reports and evidence.
10. Privacy choices and requests
Subject to applicable law and relevant exceptions, an individual may request:
- access to personal data about them;
- correction of inaccurate personal data;
- deletion of personal data;
- a portable copy of certain personal data; or
- information about our processing.
Submit requests to [email protected]. We may need to verify identity and authority. We may direct a user to their customer organization when the organization controls the relevant Customer Content.
Deletion rights are not absolute. We may retain information needed for security, fraud prevention, legal compliance, disputes, consent records, or another permitted purpose. Customer-requested historical and append-only organization records may also contain an actor's name or email.
Authorized users can update certain organization, profile, vendor, evidence, and membership information directly in the Service.
11. State privacy disclosures
U.S. state privacy laws apply based on factors such as residence, processing volume, revenue, and the context in which an individual acts. Many HIPAAWorks users act as workforce or business contacts, and state laws differ in their treatment of that context.
If a state privacy law applies, residents may have rights to know, access, correct, delete, or obtain a copy of personal data, and to appeal a denied request. Rights to opt out of sale, targeted advertising, or certain profiling may also apply. HIPAAWorks does not engage in those activities under the verified current configuration.
We will not discriminate against an individual for exercising an applicable privacy right.
California residents should note that California's business-to-business exemptions have expired, but the CCPA applies only when the statutory definition of a covered business or another covered role is met.
12. International users
The Service is currently intended for organizations and users in the United States only. Access from other countries is not supported, and we do not offer international transfer mechanisms, GDPR/UK roles, or a representative/DPO at this time.
13. Children
The Service is for organizations and authorized workforce users. It is not directed to children, and we do not knowingly collect personal data from children through the intended use of the Service.
Users must be at least 18. Contact [email protected] if you believe a child provided personal data.
14. Changes to this Notice
We may update this Notice as the Service, providers, or law changes. We will post the updated version with a new effective date. If a change materially affects how we use information already collected, we will provide additional notice or obtain consent when required.
15. Contact
Passing Lanes Solutions LLC
Privacy: [email protected]
Security: [email protected]
Support: [email protected]