Zoho Bookings protects sensitive health information of your customers that can identify an individual in a HIPAA compliant manner.
The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires Covered Entities and Business Associates to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Zoho Bookings provides certain features (as described below) to help its customers use Zoho Bookings in a HIPAA compliant manner.
HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to legal@zohocorp.com.
Zoho Bookings has provisions to protect ePHI. When collecting customer information (ePHI/PII), registration form fields can be set up for secure handling.
You can perform the following with respect to HIPAA compliance inside Zoho Bookings:
The data captured in registration form fields marked as ePHI/PII is
Data audits help you secure your customers' data and monitor for unexpected changes or usage trends. Zoho Bookings will record the audit logs ( information about every addition, update, and deletion made to customer database records) in the backend for a duration of up to one year. The audit log can be shared with you only upon request.
Drop an email to support@zohobookings.com, if you'd like to access audit logs.
Note: HIPAA support can only be invoked on guest user fields and on SingleLine, CheckBox, DropDown, Email, RadioButton, and Date custom field types. HIPAA support cannot be invoked on default fields (Name, Email, and Contact Number) and on custom MultiLine field types, as of now.
You can facilitate encryption and decryption on sensitive data for both new or existing custom form fields by marking them as ePHI/PII.
HIPAA support can be invoked on more than one field. However, when you try to mark more than one field as ePHI/PII, you might receive an error message like the below.
This is because once a registration form field is marked as ePHI/PII, it takes some time in the backend to set it up. If another field is marked as ePHI/PII simultaneously while the setup for the first field is in progress, it might disrupt the setting altogether. To avoid this, it is advised to try marking the other field as ePHI/PII at a little while later.
Learn how to use the best tools for sales force automation and better customer engagement from Zoho's implementation specialists.
If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.
You are currently viewing the help pages of Qntrl’s earlier version. Click here to view our latest version—Qntrl 3.0's help articles.