HIPAA Declaration
EverBetter LLC (“EverBetter”) is committed to protecting the privacy and security of protected health information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the Privacy Rule, Security Rule, and Breach Notification Rule.
Our commitments
- Business Associate Agreements. Any engagement involving access to patient data requires a Business Associate Agreement (BAA) to be in place before work begins. EverBetter provides a BAA as part of the vendor engagement process.
- Encryption. PHI is protected in transit and at rest with encryption protocols developed to meet or exceed global healthcare security standards.
- Patient-controlled access. EverBetter’s Solid Pod architecture makes patient data access explicit, auditable, and patient-controlled by design — directly supporting the ONC 21st Century Cures Act’s prohibition on information blocking.
- Access controls and audit. Role-based permissions govern what each staff member can see and do within the platform, and access events are logged for compliance purposes.
- Breach notification. EverBetter maintains incident response procedures aligned with HIPAA’s Breach Notification Rule, which requires covered entities to notify affected individuals within 60 days of discovery of a breach affecting 500 or more individuals.
- Workforce training. Personnel with access to PHI receive privacy and security training appropriate to their role.
Requesting documentation
For EverBetter’s technical security documentation, audit log capabilities, state privacy law compliance materials, or incident response procedures, pleasecontact our team. We are happy to review the architecture, the BAA, and our safeguards with your compliance counsel.
EverBetter LLC · 105 Continental Pl, Suite 350, Brentwood, TN 37027 ·615-270-9233