Our HIPAA Commitment
MySpark+ was built inside a working clinic, for patient data, from the first line of code. This page summarizes how the platform supports HIPAA compliance for the healthcare providers who use it. The full technical detail lives on the security page.
The Business Associate Agreement
When a clinic stores protected health information (PHI) in MySpark+, LitBiz Media, LLC acts as a Business Associate under HIPAA. A Business Associate Agreement is executed self-service during onboarding and is included in the plan price on every tier, Studio included.
Safeguards in the platform
- Encryption: PHI is encrypted in transit (TLS) and at rest, in both the database and file storage.
- Audit trail: every view and every change of patient data is logged with who, what, and when. Audit records are append-only and retained for six years.
- Access control: role-based permissions scope what front desk, providers, managers, and administrators can see and do. Sensitive actions such as patient data exports are restricted to managers and above.
- Authentication: two-factor login (TOTP) is enforced for administrator accounts. Failed logins are rate-limited.
- PHI boundary in notifications: staff notifications are structurally split so patient names can appear on the in-app notification bell, inside the platform, but never in the emails or texts that leave it.
- Communication compliance: patient consent is tracked per channel, opt-outs are honored automatically and permanently, and marketing quiet hours are enforced by the platform.
- Resilience: automated daily backups with tested restore procedures.
Patient rights
MySpark+ supports clinics in meeting HIPAA Right of Access obligations: a clinic can generate a complete export of a patient's record on request. If you are a patient seeking access to, correction of, or deletion of your records, contact your healthcare provider directly; they control your records, and their MySpark+ tools support fulfilling your request.
Our subcontractors
Infrastructure providers that handle PHI on our behalf, such as our cloud hosting and communication delivery providers, are engaged under appropriate agreements consistent with our BAA obligations.
What MySpark+ does not do
MySpark+ provides software and safeguards; it does not provide legal or compliance advice. Each clinic remains the covered entity responsible for its own HIPAA program: training its workforce, managing its policies, and using the platform's tools appropriately. Descriptions on this page are a summary; the executed BAA is the controlling document for PHI handling.
Questions
For BAA questions or a copy of your executed agreement, contact hello@litbiz.io.
MySpark