Am.care

HIPAA Compliance Agreement — v2025.1
Required before accessing Protected Health Information (PHI).

HIPAA Compliance & Data Protection Agreement

As a user of am.care with access to Protected Health Information (PHI), you acknowledge and agree to the following obligations under the Health Insurance Portability and Accountability Act (HIPAA).

1. Privacy Rule Compliance

You agree to use and disclose PHI only as permitted by the HIPAA Privacy Rule (45 CFR Part 160 and Subparts A and E of Part 164). You will access only the minimum necessary PHI to accomplish the intended purpose.

2. Security Rule Obligations

You agree to implement reasonable safeguards to protect ePHI confidentiality, integrity, and availability. This includes maintaining strong passwords, enabling MFA, and never sharing credentials.

3. Minimum Necessary Standard

You agree to access only the PHI directly relevant to your role and current task. Browsing records beyond legitimate need violates this agreement and federal law.

4. Breach Notification

You agree to immediately report any known or suspected PHI breach to compliance@am.care within 24 hours of discovery.

5. Sanctions & Enforcement

Violations may result in immediate access termination, civil penalties up to $1.5M per violation category per year, and/or criminal prosecution.

6. Business Associate Agreement

If you are a covered entity or business associate, your use of am.care is governed by the applicable BAA. You agree to comply with all terms therein.

Effective: Jan 1, 2025 • Version: v2025.1

I acknowledge and agree to: