For medical device professionals and manufacturers

HIPAA compliance across ClinicalOS, StudyOS and EvidenceOS

The Qevatrix clinical applications handle electronic protected health information as a business associate. Safeguards are built into the product — not bolted on as policy documents.

01

Business associate, contractually

Qevatrix signs a Business Associate Agreement with every covered entity before identifiable data is uploaded, and holds downstream BAAs with its hosting and AI subprocessors.

02

De-identified by default

Uploaded data sheets are classified column by column against the 18 HIPAA identifiers. Names, record numbers and contact details are removed on import, and ages over 89 are aggregated to 90+.

03

Minimum necessary, enforced

Records are coded by subject identifier and scoped to a workspace — and in EvidenceOS to the individual site. Cross-product transfers carry coded data only.

04

Every disclosure logged

Viewing, exporting or re-identifying protected data writes an append-only entry with the user, timestamp, record and stated purpose. Nobody can edit or delete the trail.

05

Automatic logoff and strong authentication

Clinical consoles idle out and sign the user back out; MFA and SSO are available, and signature actions require re-authentication under 21 CFR Part 11.

06

Breach readiness

Suspected breaches run a documented four-factor risk assessment with a notification decision and clock, so the covered entity can meet its 60-day duty.

Security Rule

Safeguard register

Each requirement, how the platform meets it, and where the covered entity retains responsibility. The same register is available inside every clinical console.

Administrative safeguards

Risk analysis

45 CFR 164.308(a)(1)(ii)(A)

Conduct an accurate and thorough assessment of the risks to the confidentiality, integrity and availability of electronic protected health information.

Platform risk assessment maintained in the HIPAA compliance module and reviewed at least annually and after any material architectural change. Automated security scanning runs continuously against the hosted database and application.

Your responsibility: Record your own site-level and workforce risk assessment against this register.

Workforce security and authorisation

45 CFR 164.308(a)(3)

Ensure workforce members have appropriate access to ePHI and prevent access by those who do not.

Every record is scoped to a single company workspace with row-level security. Roles (owner, admin, member) and, in EvidenceOS, per-site membership limit access to the participants a user is responsible for.

Your responsibility: Keep the user list current and remove leavers on their last working day.

Information access management — minimum necessary

45 CFR 164.308(a)(4)

Restrict access and disclosure of ePHI to the minimum necessary for the purpose.

Direct identifiers are detected and removed by default at import; clinical records are coded by subject identifier. Cross-product transfers (for example a registry complaint sent to QualityOS) carry coded, minimum-necessary data only.

Security awareness and training

45 CFR 164.308(a)(5)

Implement a security awareness and training programme for all workforce members.

HIPAA awareness training is tracked as a controlled training record with assignment, completion and effectiveness evidence.

Your responsibility: Assign the HIPAA awareness curriculum to every workforce member with access to the console.

Security incident procedures

45 CFR 164.308(a)(6)

Identify, respond to and document security incidents and their outcomes.

Security findings are triaged in an append-only security register with disposition, rationale and the clearing user recorded.

Contingency plan

45 CFR 164.308(a)(7)

Establish data backup, disaster recovery and emergency mode operation plans.

Managed Postgres with point-in-time recovery and automated daily backups; object storage is replicated. Recovery objectives are documented in the contingency plan record.

Physical safeguards

Facility access controls

45 CFR 164.310(a)(1)

Limit physical access to systems and the facilities in which they are housed.

All processing runs in SOC 2 / ISO 27001 certified cloud regions. Qevatrix personnel have no physical access to hosts; there is no on-premise component holding ePHI.

Device and media controls

45 CFR 164.310(d)(1)

Govern receipt, removal, reuse and disposal of hardware and media containing ePHI.

ePHI is never written to endpoint devices by the platform; exports are generated on demand, logged, and delivered over TLS. Cloud media are cryptographically erased on decommission.

Your responsibility: Control local copies of any export you download.

Technical safeguards

Access control and unique user identification

45 CFR 164.312(a)(1)

Allow access only to authorised persons, with unique user IDs and automatic logoff.

Named accounts only — no shared logins. Sessions idle out automatically in the clinical consoles and the user must re-authenticate before identifiable data is shown again.

Audit controls

45 CFR 164.312(b)

Record and examine activity in systems that contain or use ePHI.

An append-only PHI access log captures who viewed, exported or re-identified data, when, from which record and for what stated purpose. Entries cannot be edited or deleted by any application role.

Integrity

45 CFR 164.312(c)(1)

Protect ePHI from improper alteration or destruction.

Clinical and quality records are versioned and append-only; corrections create a new version with reason-for-change, and 21 CFR Part 11 electronic signatures bind the signer, timestamp and meaning.

Person or entity authentication

45 CFR 164.312(d)

Verify that the person seeking access is the one claimed.

Email plus password or federated sign-in, with multi-factor authentication and SSO available. Signature actions require the signer to re-enter their credentials.

Transmission security

45 CFR 164.312(e)(1)

Guard against unauthorised access to ePHI transmitted over a network.

TLS 1.2+ in transit for every request, AES-256 at rest for the database and object storage. AI processing runs against de-identified content unless an identifiable review is explicitly authorised.

Minimum necessary at field level

45 CFR 164.502(b) / 164.514(d)

Limit ePHI use and disclosure to the minimum necessary to accomplish the purpose.

Uploaded data sheets are classified column by column against the 18 HIPAA identifiers. Identifiers are removed by default; retaining them requires an explicit authorisation choice which is itself logged.

Organisational requirements

Business associate contracts

45 CFR 164.308(b)(1)

Obtain satisfactory assurances from business associates that they will safeguard ePHI.

Qevatrix executes a Business Associate Agreement with each covered entity and holds downstream BAAs with its hosting and AI subprocessors. Subprocessors are listed in the BAA register.

Your responsibility: Execute the BAA before uploading any identifiable data.

Breach notification

Breach notification

45 CFR 164.404 – 164.410

Notify affected individuals, the Secretary and, where required, the media following discovery of a breach of unsecured PHI.

Suspected breaches are raised as security incidents with a documented four-factor risk assessment, notification decision and clock. Qevatrix notifies the covered entity without unreasonable delay and within 60 days of discovery.

Your responsibility: Own the individual and Secretary notifications as the covered entity.

Request the BAA and the HIPAA pack

The pack includes the Business Associate Agreement, subprocessor list, risk assessment summary, de-identification methodology and the breach notification procedure.