Legal & compliance hub.

Trust for clinics. Privacy for patients. Clear terms for between-visit texting. All in one place.

Policy index

Fifteen policies, not three bullets.

Helose maintains a written compliance program reviewed annually and on material change. Summaries below; full policy text available on procurement request.

# Policy Scope
01 HIPAA Privacy Policy Patient rights, permitted uses, and complaint handling.
02 HIPAA Security Policy Administrative, physical, and technical safeguards for PHI.
03 Access Control Policy Least privilege, authentication, and access reviews.
04 Incident Response Plan Detection, containment, notification, and recovery.
05 Data Retention & Destruction Seven-year audit retention, secure deletion, destruction certificates.
06 Acceptable Use Policy Workforce and contractor expectations for systems and data.
07 Workforce Training Plan Annual HIPAA training and onboarding requirements.
08 Breach Notification Plan Customer and regulatory notification timelines.
09 Risk Management Policy Annual risk assessment and remediation tracking.
10 Vendor / Subprocessor Management Due diligence, BAAs, and ongoing vendor reviews.
11 Encryption Policy TLS in transit, encryption at rest, and key management.
12 Logging & Audit Policy Hash-chained audit log, retention, and review cadence.
13 Business Continuity / DR Backup, recovery objectives, and failover procedures.
14 Software Development Lifecycle Secure development, code review, and release gates.
15 Change Management Policy Production change approval, rollback, and documentation.

Questions?

Procurement & questionnaires: contact@helose.com
Security inquiries: security@helose.com
Privacy complaints: privacy@helose.com