HIPAA Compliance
Last Updated: September 30, 2026
Our Role
DashQuill Technologies LLC is a business associate to the medical practices that use our services. Every practice signs a Business Associate Agreement (BAA) with us as part of onboarding, before any protected health information (PHI) is handled. The BAA governs how we use, disclose, safeguard and return PHI. Where the BAA and our other agreements differ on PHI, the BAA controls. This page summarizes the commitments in that BAA and in our Software as a Service Agreement; the signed documents are the authoritative versions.
Data Protection & Infrastructure
PHI is encrypted in transit using TLS and at rest using AES-256. Our infrastructure is hosted in U.S. regions. Support and maintenance access to PHI is limited to the minimum necessary, restricted to trained personnel, and logged, wherever those personnel are located, as set out in the BAA.
We maintain a written information security program, regular security assessments and testing, regular backups with redundant storage, and documented business continuity and disaster recovery procedures that are tested regularly.
Access Controls & Audit Logs
Access to PHI is limited by role-based access control, and multi-factor authentication is part of our access controls. Our staff access PHI only to provide technical support, maintenance, troubleshooting or error resolution, limited to the minimum necessary, restricted to trained personnel with a legitimate need, and typically in response to a support request the practice initiated or a logged system issue. We do not routinely access PHI.
Audit logs record access to, modification of and deletion of PHI, with timestamps and user identifiers. These logs support the practice's compliance reviews and any incident investigation.
Use of PHI, Subcontractors & AI Processing
PHI remains the property of the practice. We use and disclose it only to perform the services, for our own proper management and administration, to provide data aggregation services relating to the practice's health care operations, and as required by law. We may de-identify PHI only as necessary to perform our obligations, and we do not use de-identified data for any other purpose without the practice's written consent. PHI is never used for marketing or advertising.
Any subcontractor that creates, receives, maintains or transmits PHI on our behalf is bound by a written agreement to the same restrictions and conditions that apply to us, and we remain responsible for their acts and omissions.
Our services include AI-enabled features such as fax classification and patient matching, document summaries and draft visit notes. That processing is covered by the BAA, and our subcontractor obligations above apply to it. AI features operate on a suggestion-only basis: their outputs do not modify, import, file or route any patient record or EHR data until a member of the practice reviews and confirms the action. AI outputs are probabilistic and can be wrong, which is why the practice's review is required before any use in patient care or in the chart.
Incident & Breach Notification
We maintain a documented incident response plan. We notify the practice in writing of any security incident or non-permitted use or disclosure of PHI without unreasonable delay and no later than five business days after becoming aware of it. If a breach of unsecured PHI is confirmed, we notify the practice no later than fifteen calendar days after discovery, provide the information required under 45 CFR § 164.410(c), cooperate with the practice's investigation and obligations, and reimburse reasonable notification and mitigation costs to the extent the breach was caused by us. Unsuccessful or routine events such as pings, scans and failed login attempts that do not result in unauthorized access to PHI are not reported individually.
Individual Rights
When a practice asks, we make PHI available for patient access within fifteen days, incorporate amendments within fifteen days, and provide the information needed for an accounting of disclosures within fifteen days, or within thirty days where more time is reasonably required.
Retention, Export & Return of PHI
PHI is retained for the term of the practice's agreement and in accordance with the retention period in its Order of Services and applicable law. For at least thirty days after termination, the practice can access and export its data in a standard machine-readable format, and we assist with that export on request. After termination we return or destroy all PHI within thirty days. Where return or destruction is not feasible, we retain only what is necessary, continue to protect it under the BAA, and limit further use to the purposes that make return or destruction infeasible. A practice can also request deletion of its data at any time after exporting it.
Compliance Documentation
All staff who handle or have access to PHI receive HIPAA training, and we conduct ongoing risk assessments. On reasonable written request, including during a practice's vendor onboarding or periodic compliance review, we provide a summary of our information security program and, when available, our most recent SOC 2 or comparable third-party security assessment report. We are currently pursuing SOC 2 Type II. There is no government-issued "HIPAA certification"; what we can provide is documentation of the safeguards above and our BAA. We are also working toward WCAG 2.1 AA accessibility standards.
Contact Us
For questions about HIPAA compliance, security practices, or to request a Business Associate Agreement:
- Email: contact@dashquill.com
- Phone: (425) 600-2019
