HIPAA & PHI Practices

SovaCare acts as a Business Associate when it creates, receives, maintains or transmits PHI on behalf of a covered entity pursuant to a Business Associate Agreement.

Important

This page is a Business Associate statement, not a covered-entity Notice of Privacy Practices. Your clinic (the Covered Entity) is responsible for notifying patients of their privacy rights. BAA available for covered entities.

Designed to support HIPAA-compliant healthcare operations.

1. Our Role Under HIPAA

Sova Holdings Group Inc. operates SovaCare as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when we handle PHI for a covered entity. We:

  • Create, receive, maintain, and transmit Protected Health Information (PHI) on your behalf pursuant to a BAA
  • Comply with the HIPAA Security Rule (45 CFR §§ 164.300–320)
  • Follow applicable Privacy Rule obligations of a business associate (45 CFR §§ 164.500–508)
  • Execute a Business Associate Agreement before handling PHI for a covered entity

2. PHI We Handle

SovaCare may access the following types of PHI when instructed by the covered entity:

  • Patient demographics (name, DOB, contact info)
  • Medical history (diagnoses, medications, allergies, procedures)
  • Encounter records and clinical notes
  • Laboratory and radiology results
  • Insurance information
  • Consent and authorization records

3. Permitted Uses and Disclosures

SovaCare uses and discloses PHI only as permitted by:

  • The Business Associate Agreement with your organization
  • Your written instructions
  • HIPAA (for example, as required by law)

SovaCare does NOT:

  • Use PHI for marketing or fundraising
  • Sell PHI to third parties
  • Use PHI for purposes other than those specified in the BAA

4. Safeguards

SovaCare implements security measures to protect PHI:

Administrative

  • Workforce security policies and access controls
  • Information access management (role-based access)
  • Security awareness training for staff with PHI access
  • Incident response procedures

Physical

  • Infrastructure hosted in Microsoft Azure regions used for U.S. healthcare workloads
  • Restricted physical access to data-center facilities (cloud provider controls)

Technical

  • Encryption in transit (TLS 1.2+)
  • Encryption at rest (AES-256)
  • Audit logging and monitoring
  • Multi-factor authentication
  • Vulnerability management

5. Subprocessors

We distinguish vendors that process PHI from vendors that never receive PHI.

PHI-processing subprocessors

Vendors that create, receive, maintain, or transmit PHI on our behalf (for example, Microsoft Azure for hosting) are engaged under appropriate contractual assurances consistent with HIPAA business-associate requirements.

Vendors that do not receive PHI

  • Stripe: Payment processing for clinic subscription billing (not a clinical PHI store)
  • Public-site analytics: Marketing analytics are restricted to approved public-facing pages and are configured so that PHI is not intentionally transmitted to analytics providers. Google does not offer a Business Associate Agreement for Google Analytics; we do not treat GA as a HIPAA business associate, and we do not place analytics tags on authenticated clinical areas that could expose PHI.

6. Patient Rights

Under HIPAA, patients have rights of access, amendment, accounting of disclosures, restriction requests, and confidential communication. Patients should direct these requests to their clinic, not to SovaCare. Your clinic will coordinate with us as needed under the BAA.

7. Breach Notification

If a breach of unsecured PHI occurs:

  • SovaCare will notify your clinic without unreasonable delay
  • We will provide details of the breach, affected individuals (to the extent known), and remediation steps
  • Your clinic is responsible for notifying affected patients and regulators as required by law

For breach inquiries, contact: admin@sovacare.health

8. Audit Logging

SovaCare maintains audit logs of PHI access, modifications, user login events, and relevant system events.

Audit logs are retained for seven years pursuant to SovaCare policy and applicable contractual/legal requirements. Your clinic can request audit reports as provided in the BAA.

9. Data Retention

SovaCare retains PHI according to your clinic's data retention policy, the BAA, and applicable law:

  • Patient records: Retained during the active relationship and per your retention policy
  • Audit logs are retained for seven years pursuant to SovaCare policy and applicable contractual/legal requirements.
  • Backup data: Retained per disaster recovery policy

Upon clinic request or contract termination, SovaCare will delete or return PHI as specified in the BAA.

10. Business Associate Agreement

A Business Associate Agreement must be executed before SovaCare handles any PHI. The BAA specifies permitted uses, security obligations, breach notification, and data return or destruction.

For a copy of the BAA, contact: admin@sovacare.health

11. Questions

For questions about this statement:

Sova Holdings Group Inc.

Email: admin@sovacare.health

Washington, D.C.

Patients may also file a complaint with the U.S. Department of Health & Human Services Office for Civil Rights (OCR).

12. Effective Date

This statement is effective as of August 2026 and applies to PHI processed by SovaCare as a Business Associate.