STFE's Role Under HIPAA
STFE Systems Inc. is a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 CFR Parts 160 and 164). Your facility โ as the licensed healthcare provider โ is the Covered Entity.
As a Business Associate, STFE:
- Creates, receives, maintains, and transmits PHI only on behalf of your facility
- Uses PHI only to perform the clinical decision support services described in the BAA
- Does not use PHI for advertising, marketing, or any purpose not specified in the BAA
- Maintains the technical, physical, and administrative safeguards required by the HIPAA Security Rule
- Reports any breach of unsecured PHI within 72 hours of discovery
- Ensures downstream subcontractors (AWS, etc.) are bound by equivalent obligations
What PHI the Platform Processes
When your facility uses STFE for admission evaluations, the following types of PHI may be processed:
- Patient clinical data submitted at intake (diagnoses, vital signs, functional assessments, medications)
- De-identified reference IDs linked to clinical evaluation records
- MDS assessment pre-population data
- Admission decision records and clinical audit trails
Shadow Audit: The bulk shadow audit feature is designed to operate on de-identified data. Facilities should remove all direct identifiers (name, DOB, MRN, SSN, Medicare ID) before submitting historical data for shadow audit. If PHI is inadvertently submitted, it is governed by the BAA.
Technical Safeguards
๐ Encryption at Rest
All data encrypted with AES-256. Database-level encryption on AWS RDS.
๐ Encryption in Transit
All communications over TLS 1.3. No unencrypted data transmission permitted.
๐ค Access Controls
Role-based access (5 roles). Least-privilege principle. Multi-factor authentication for admin access.
๐ Audit Logging
Immutable SHA-256 hash-sealed audit records on every PHI access and clinical evaluation.
โ๏ธ HIPAA-Eligible Infrastructure
All data stored and processed on AWS HIPAA-eligible services (EC2, RDS, ElastiCache) in us-east-1.
๐ Annual Security Review
Third-party penetration testing and a SOC 2 Type II audit are in progress. Results available under NDA.
Physical and Administrative Safeguards
- No PHI on workstations: All PHI remains in cloud infrastructure. Engineers access production only through bastion hosts with full session logging.
- Background checks: All staff with potential PHI access undergo background verification.
- Training: All staff complete annual HIPAA privacy and security training.
- Incident response: Written incident response plan. Breach notification within 72 hours of discovery. HHS notification within 60 days as required by the Breach Notification Rule (45 CFR ยง164.400).
- Minimum necessary: Only clinical data required for the evaluation is processed. No additional data is requested or retained.
Subcontractors (Downstream Business Associates)
STFE uses the following subcontractors who may have access to PHI. Each is bound by a Business Associate Agreement with STFE:
- Amazon Web Services (AWS): Infrastructure hosting. AWS HIPAA-eligible services. AWS BAA in place. AWS HIPAA Compliance โ
The following vendors do not have access to PHI:
- Stripe (payment processing โ handles only billing data, never clinical data)
- Datadog (performance monitoring โ receives only anonymized metrics)
Patient Rights (As Covered by the Covered Entity)
As a Business Associate, STFE supports Covered Entities in fulfilling patient rights under HIPAA:
- Right of Access: STFE can provide facility-specific data exports to support patient access requests within 30 days
- Right to Amendment: Corrections to clinical evaluation records are logged with an audit trail
- Right to an Accounting of Disclosures: STFE maintains a complete audit log of all PHI disclosures that can be exported on request
- Right to Restriction: Implemented through facility-level access controls
Patients should contact their healthcare facility (the Covered Entity) directly to exercise these rights. STFE will cooperate with the Covered Entity's requests.
Request a Business Associate Agreement
A BAA is required before submitting any PHI. We typically turn around a signed BAA within 3โ5 business days.
Request BAA โ compliance@stfe.ioReporting a HIPAA Concern
If you believe STFE has violated your facility's HIPAA rights or any provision of our BAA:
- Contact STFE directly: compliance@stfe.io or +1 (302) 555-1911 (24/7 compliance hotline)
- File a complaint with HHS: You may file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint
STFE will not retaliate against any facility or individual for filing a good-faith HIPAA complaint.