MedTalk AI Logo

HIPAA Compliance

MedTalk AI is committed to safeguarding your Protected Health Information (PHI) in compliance with HIPAA. Below, we outline how we ensure the security of your health data and your rights under HIPAA.

Protect your customers' ePHI data

Strong controls + documented governance = reliable PHI protection for capturing, transcribing & sharing clinical context.

Privacy & Security Safeguards

We implement administrative, physical & technical safeguards to protect PHI confidentiality, integrity, and availability under HIPAA.

Risk Analysis & Management

We conduct periodic risk assessments, remediation tracking, and control testing to ensure compliance with HIPAA.

Training & Awareness

We provide team-wide HIPAA training, role-based responsibilities, and clear do’s/don’ts for PHI handling.

Business Associate Agreements

We execute BAAs with customers/vendors to ensure subprocessors are bound by HIPAA obligations.

Incident Response & Reporting

We have playbooks for triage, containment, forensics, & notifications, with documented RACI included.

Access Controls

We ensure least-privilege RBAC, support SSO/MFA, session controls, and minimum-necessary alignment under HIPAA.

Audit Controls

We maintain comprehensive audit logging, periodic reviews, export options, and customer audit support to meet HIPAA standards.

Data Residency

We ensure region-aware hosting & retention controls aligned to HIPAA and regulatory needs.

§1

Overview

MedTalk AI is committed to protecting your Protected Health Information...
§2

The Information We Collect

Protected Health Information (PHI) refers to any health information that can be linked to a specific individual...
• Identity Data (Name, Date of Birth, Gender) • Health Data (Diagnosis, Treatment, Prescriptions, Medical History) • Contact Data (Phone number, Email address, Postal Address) • Payment Data (Insurance information, Billing details) • Usage Data (IP Address, Device information, interaction with our services)
§3

How We Collect Personal Information

• Directly from healthcare providers or patients. • Through electronic health records (EHR) systems ...
§4

Your Rights Under HIPAA

• The Right to Access ... • The Right to Correction ... • The Right to Erasure ... • The Right to Limit Disclosure ... • The Right to Portability ... • The Right to File a Complaint ...
§5

Why We Collect, Use, and Disclose Personal Information

• To deliver healthcare-related services, including transcription and reporting. • To comply with healthcare regulations and obligations. • To communicate with patients and healthcare providers regarding services and updates. • To improve healthcare services and technologies through data analysis and research. • To maintain secure and reliable health records.
• Consent: You have given explicit consent ... • Treatment: Processing PHI is necessary ... • Legal Requirements: ... • Administrative and Operational Purposes: ...
§6

Data Processing and Transfers

We process PHI to provide healthcare services, and some of the data may be shared with third-party vendors...
§7

Cookies and Tracking Technologies

We use cookies and similar technologies to enhance your experience...
§8

Data Security

We implement appropriate technical and organizational measures...
§9

Third-Party Data Sharing

We may share your PHI with third parties only under the following circumstances...
§10

HIPAA Compliance Updates

We periodically review our practices and update this Privacy Policy...
§11

For Any Questions or Notices, Please Contact Us at:

Faz Australia Pty Ltd (ABN 67 608 122 514)