HIPAA Alignment Statement
Placeholder draft — requires legal review before publication.
HDT Partners operates as a business associate to the healthcare organizations we serve. Our workflows, access controls, and data handling practices are designed in alignment with the HIPAA Privacy and Security Rules.
How we work. HDT operates inside each client's existing practice management and EHR systems under client-issued credentials and role-based permissions. Client data remains in client systems — we do not extract, migrate, or warehouse PHI on our own infrastructure as part of standard engagements.
Business Associate Agreements. Every engagement involving access to PHI is governed by an executed BAA defining permitted uses, safeguards, and breach-notification obligations.
Workforce and access controls. Team members receive HIPAA training, access is limited to the minimum necessary for their assigned functions, and access is revoked promptly on role change or engagement end.
Questions about our privacy and security practices can be directed to Contact@hdtpartners.com.