Legal & compliance hub.
Trust for clinics. Privacy for patients. Clear terms for between-visit texting. All in one place.
Start here
Public documents.
-
Clinics
Terms of service
The agreement that governs clinic use of Helose. Fees, acceptable use, liability, and governing law.
-
Clinics
Trust & security
For clinics, procurement, and IT. BAA, controls, and clinic responsibilities.
-
Patients + clinics
Data & privacy
Plain-language privacy for patients and clinic staff. Encryption, access, and your choices.
-
Patients
Messaging terms
Patient opt-in terms for health-related texts. Channel limits, STOP, and your responsibilities.
-
Clinics
Business Associate Agreement
Click-through BAA at clinic signup. Counter-signed BAA available on annual contracts.
Policy index
Fifteen policies, not three bullets.
Helose maintains a written compliance program reviewed annually and on material change. Summaries below; full policy text available on procurement request.
| # | Policy | Scope |
|---|---|---|
| 01 | HIPAA Privacy Policy | Patient rights, permitted uses, and complaint handling. |
| 02 | HIPAA Security Policy | Administrative, physical, and technical safeguards for PHI. |
| 03 | Access Control Policy | Least privilege, authentication, and access reviews. |
| 04 | Incident Response Plan | Detection, containment, notification, and recovery. |
| 05 | Data Retention & Destruction | Seven-year audit retention, secure deletion, destruction certificates. |
| 06 | Acceptable Use Policy | Workforce and contractor expectations for systems and data. |
| 07 | Workforce Training Plan | Annual HIPAA training and onboarding requirements. |
| 08 | Breach Notification Plan | Customer and regulatory notification timelines. |
| 09 | Risk Management Policy | Annual risk assessment and remediation tracking. |
| 10 | Vendor / Subprocessor Management | Due diligence, BAAs, and ongoing vendor reviews. |
| 11 | Encryption Policy | TLS in transit, encryption at rest, and key management. |
| 12 | Logging & Audit Policy | Hash-chained audit log, retention, and review cadence. |
| 13 | Business Continuity / DR | Backup, recovery objectives, and failover procedures. |
| 14 | Software Development Lifecycle | Secure development, code review, and release gates. |
| 15 | Change Management Policy | Production change approval, rollback, and documentation. |
Questions?
Procurement & questionnaires: contact@helose.com
Security inquiries: security@helose.com
Privacy complaints: privacy@helose.com