Atlas Health Group

Compliance

HIPAAPolicy.

Comprehensive guidelines for safeguarding the confidentiality and security of member information within our CalAIM Enhanced Care Management and Community Supports programs.
Hands reviewing printed privacy documents beside a laptop

Purpose

Establish comprehensive guidelines for safeguarding member information in compliance with HIPAA and the California Confidentiality of Medical Information Act (CMIA).

Scope

Applies to all employees, contractors, volunteers, and affiliated personnel with access to confidential member information.

Definitions

Confidential Member Information includes any personal, medical, or financial information that can identify a member, including all Protected Health Information (PHI) as defined by HIPAA.

Access control

We follow the principle of least privilege. Secure credentials are required for all systems containing PHI and access rights are audited regularly. Sharing credentials is prohibited.

Physical security

Physical documents are stored in locked cabinets or rooms with controlled access. Workstations are locked when unattended and screens are positioned to avoid casual observation.

Training & enforcement

All personnel complete HIPAA training at onboarding and annually thereafter. Unauthorized disclosure may result in disciplinary action up to and including termination.

Questions?

Talk to a real person about your information.

Our team can walk you through any of this in plain language, in your language, at no cost.