Introduction
The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires
Covered Entities and Business Associates
to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals.
Qntrl does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Qntrl provides certain features (as described below) to help its customers use Qntrl in a HIPAA compliant manner.
HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to
legal@zohocorp.com
.
HIPAA compliance in Qntrl
Workflows of health care organizations can be automated using Qntrl and hence safely preserving the electronic health records of these organizations in Qntrl is crucial.
To ensure the security of your information, we support the following actions in Qntrl:
-
Mark ePHI (Electronic Protected Health Information) or Encrypt fields in forms.
-
Set roles and privileges for users.
-
Export audit logs to monitor operational activities.
You can mark a field as ePHI if it contains the health information of your customers or patients. ePHI field values will be
encrypted
, both in transit and at rest.
To mark fields that contain personal health data:
- Navigate to Boards , hover over any specific board in the left panel and click to choose Manage Board . (or)
- Navigate to to select a board. Learn more.
-
You will be navigated to
Step 1: Create Form
. Hover over the field that you would like to mark as PHI and select .
-
Choose
Edit Properties
in the dropdown.
-
Toggle the button next to Encrypt or PHI to turn it ON/OFF.
-
Confirm your action and click
OK
.
-
Save
the Board.
Set roles and privileges for users
Each user added to Qntrl can be set a
profile
and multiple
roles
based on which their level of data access will depend in the Qntrl organization. Additionally, each field in the form can also be set privileges for
read or write access
.
Audit logs
Audit log allows you to track the actions executed by users in your organization along with a trail of automated events that are configured to be triggered. If you want to preserve this log for a long period, you can periodically export it using the
Export Audit Log
option.
If you have any other queries on the features of Qntrl that supports HIPAA compliance, please email us at
support@qntrl.com
.
Related Articles
Zoho Directory in Qntrl
What is Active Directory? Active Directory (AD) by Microsoft is a domain management system for centralized networks. Using AD, you can add users, define their privilege, store and manage information, and authorize and authenticate user accounts. What ...
Qntrl for Zoho Cliq
Zoho Cliq is a team communication application that simplifies collaboration and promotes organized conversations in the workplace. Benefits of the Extension By integrating Zoho Cliq with Qntrl, users can create new cards and work on them in Qntrl, ...
Zoho Analytics in Qntrl
Zoho Analytics is a business intelligence platform that structures data into insightful reports and dashboards. It assists you with analyzing organizational data to generate visual graphs, making inferences, and discovering hidden insights to empower ...
Settings in Qntrl Studio
Create and track extensions with the help of features like Functions, Executions, Connections, Developers, and Audit Logs. This helps create more advanced extensions and contributes to a versatile workspace in Qntrl Marketplace. Developers Add users ...
Connections in Qntrl
Qntrl allows users to integrate with internal Zoho applications and other third-party applications using Connections. Connections can be established in Qntrl by configuring the custom functions. Please create relevant custom functions before creating ...