HIPAA and Security
Observer Medical keeps what it records on a device inside the clinic. This page explains how that fits the HIPAA Privacy, Security and Breach Notification Rules (45 CFR Parts 160 and 164), what we commit to, and what stays the clinic's responsibility. It is a summary for practice managers and privacy officers, not legal advice.
Who is who under HIPAA
- The clinic is the covered entity. It decides to use the device, owns everything the device records, and answers to its patients for their information.
- Golden Observer is a business associate. Because our device holds protected health information (PHI) for the clinic, we sign a Business Associate Agreement (BAA) with every clinic before a device is installed.
- Why recording is permitted. HIPAA lets a covered entity use PHI for its own health care operations — including quality assessment and improvement, training, and business management (45 CFR 164.501 and 164.506). Recording the front desk to understand and improve how the practice runs is used for those purposes.
What we commit to in the BAA
- Use or disclose PHI only as the BAA allows or the law requires.
- Keep appropriate administrative, physical and technical safeguards and comply with the HIPAA Security Rule (45 CFR Part 164, Subpart C) for electronic PHI.
- Report to the clinic any use or disclosure the BAA does not allow, any security incident, and any breach of unsecured PHI, without unreasonable delay and within the time 45 CFR 164.410 requires, with the information the clinic needs to notify patients.
- Use no subcontractor that receives PHI. If that ever changes, the subcontractor must agree in writing to the same restrictions.
- Help the clinic answer patients' requests to see, amend or receive an accounting of their information.
- Make our records available to the Secretary of Health and Human Services when required.
- When the service ends, erase the device, keep no copies, and give the clinic a certificate of erasure.
The clinic can ask for the full BAA at any time before signing anything.
How the device protects patient information
| Location | Audio, transcripts and reports stay on the device in the clinic. Nothing it records is sent to us or to any cloud service. |
|---|---|
| Our access | None. We cannot see or hear what the device records. |
| Access control | Only staff the clinic chooses, behind a PIN. The screen locks itself when nobody is using it. |
| Audit record | Every view, setting change and update is recorded on the device for the clinic's privacy officer. |
| Retention | The clinic sets how long recordings are kept and can delete them at any time. |
| Patients | The device recognises enrolled staff by voice. It never builds a voice profile of a patient or tries to identify one. |
| Patient rooms | The patient-room setting keeps no words and no pictures. |
| End of service | The device is erased and a certificate of erasure is given to the clinic. |
What the clinic does
- Tell patients. Add one sentence, which we supply, to the Notice of Privacy Practices or intake form, and keep the device in plain view.
- Tell staff. Add one line, which we supply, to the staff handbook. In Illinois, Texas and Washington, collect each staff member's written consent before the device learns their voice; we supply the form.
- Include the device in the risk analysis required by 45 CFR 164.308(a)(1). We supply a ready-made section describing it.
- Manage access. Give PINs only to staff who need them, and remove access when someone leaves.
- Answer patients. Requests from patients about their information go to the clinic, which may ask us for help under the BAA.
- Check state law. Some states have recording or biometric laws stricter than HIPAA. The clinic's own counsel should confirm the notice wording for its state.
Documents we provide
- Business Associate Agreement
- Pilot Agreement and this User Agreement
- Patient notice sentence and staff handbook line
- Staff voice consent form (for Illinois, Texas and Washington)
- Risk analysis section describing the device
Reporting a concern
To report a suspected security incident, or to ask for any document above, write to [email protected]. Please describe the concern without including patient information.
Observer Medical is an operations tool. It is not a medical device, is not used for diagnosis or treatment, and is not part of any patient's medical record.