Newsroom
Executive Bio
Frequently Asked Questions
HIPAA Compliance
Contact Us
 

HIPAA Compliance

 
 
 

The Chart-MD, LLC websites are designed by a physician for ease of use and security.  These sites have several security measures to protect confidential information. The sites of Chart-MD, LLC use Secure Socket Layer (SSL) encryption technology when transmitting information to and from our servers.  All information is password protected.  All data is stored on a secure server with backup onto a second secure server. Chart-MD, LLC does not sell or share patient-identifying information, including email addresses. 


Chart-MD is HIPAA compliant.  HIPAA requires that medical records remain confidential through implementation of standards that maintain confidentiality and portability of patient records.  This means that records must be transmitted, stored, and processed in a secure environment.  All documents are maintained for six years.  This also requires that all records about a patient must be stored for two years after the patient's death.


The websites of Chart-MD, LLC maintain HIPAA compliance.  To ensure the confidentiality, integrity, and availability of all electronic protected health information, all transmission of medical records and information occurs through encryption, up to 256 bit. Encryption is the process of scrambling data into an undecipherable format that can only be returned to a readable format with the proper decryption key.  A SSL certificate serves as an electronic "passport" that establishes an online entity’s credentials when doing business on the Web. When an Internet user attempts to send confidential information to a Web server, the user’s browser accesses the server’s digital certificate and establishes a secure connection.


All medical data and emails are stored securely on a private dedicated secure server.  All information stored on the websites is backed up every eight hours on a second secure dedicated server that is remotely located from the primary server.


The websites of Chart-MD, LLC require authentication to access any secure data.  This is done through the creation of personal passwords and usernames.  The user will be logged off of the system at timed intervals or on-demand to prevent unintended or un-authorized viewing of confidential medical records.  The user must always enter their username and password to access confidential information.    All usernames and passwords are confidential and can be changed by the user on demand.  All internal e-mail is encrypted and stored on the system.  This allows documentation of any communication between physicians and patients.  Additionally this documentation is encrypted and stored in a method that maintains confidentiality by not requiring the users to use traditional email accounts.


These secure servers used for the websites of chart M.D. are monitored for unauthorized access 24 hours a day.  Once the data is entered into the system it cannot be modified or erased by the user.  The deluxe SSL certificates used by the sites of Chart-MD ensures that Chart-MD controls the domain for which the certificate is being requested.  It means that the certificate is being issued to an organization that is currently registered with a government authority.  It also ensures that the individual requesting the certificate is associated with the entity named in the certificate (if applicable).