HIPAA, Business Associate & Data Processing
How QuezBridge handles protected health information as a Business Associate to covered-entity clinicians — the boundary, safeguards, subprocessors, and how a Business Associate Agreement is executed.
Effective July 20, 2026 · Last updated: July 20, 2026
1. Our role
When a covered-entity clinician or practice uses QuezBridge to create, receive, maintain, or transmit protected health information ("PHI"), QMM, Inc. acts as a Business Associate under the Health Insurance Portability and Accountability Act ("HIPAA") and the HITECH Act. Our handling of PHI is governed by a Business Associate Agreement ("BAA") between us and the covered entity.
We will execute a BAA with your practice before any PHI is processed in production. The platform ships with production PHI handling disabled until the covered entity has a signed BAA in place.
2. The PHI boundary
The platform is built as two separate planes so that health information never mixes with the public marketing site or with any advertising or analytics system:
- Non-PHI plane — the public website, marketing, and general business functions. It is designed to never receive PHI.
- PHI plane — the clinical environment where patient data is processed under the BAA, on infrastructure covered by a provider BAA, isolated by strict access controls and encryption.
Our controlling rule is simple: PHI never leaves the covered boundary. It is not sent to any advertising platform, is not used to build or train third-party models, and is not exposed to systems outside the BAA-covered environment.
3. Permitted uses and safeguards
As a Business Associate we use and disclose PHI only as the BAA and HIPAA permit — to provide the Services to the covered entity, for our proper management and administration, and as required by law. We maintain administrative, physical, and technical safeguards consistent with the HIPAA Security Rule, including:
- Encryption of PHI in transit and at rest.
- Role-based, least-privilege access with authentication controls, and audit logging of access to PHI.
- Workforce training and confidentiality obligations.
- Written agreements requiring our subcontractors that handle PHI to provide equivalent protections.
4. Data ownership and patient rights
The covered entity and its patients own the health information. We support the covered entity in meeting patient rights under HIPAA, including access, amendment, and an accounting of disclosures, and we return or securely destroy PHI as directed at the end of the engagement, as the BAA specifies.
5. Breach notification
If we discover a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and within the timeframe the BAA and HIPAA require, and cooperate in the covered entity’s response and notification obligations. We also recognize obligations under the FTC Health Breach Notification Rule where it applies to non-HIPAA health data.
6. Special categories and additional laws
Certain information carries heightened protections that we honor in addition to HIPAA, including psychotherapy notes, substance-use-disorder records under 42 CFR Part 2 where applicable, minors’ information and consent rules, and state privacy laws (for example consumer-health laws such as Washington’s My Health My Data Act). Recording or transcription features, where offered, operate only with the consents that applicable law requires.
7. Subprocessors
PHI is processed only on infrastructure and with subprocessors covered by appropriate agreements. The current subprocessor list is maintained on the Security & Compliance page and is available to customers, who are notified of material changes as the BAA provides.
8. Requesting a BAA
Practices can request our Business Associate Agreement before onboarding. Contact privacy@quezbridge.com or legal@quezbridge.com to begin.