HIPAA Notice of Privacy Practices
Last updated: March 2026
Important Notice
Sanum's current MVP version does not store or transmit Protected Health Information (PHI). This notice describes our practices when PHI features are activated for organizations with a signed Business Associate Agreement (BAA).
1. Our Commitment to Privacy
Sanum is committed to protecting the privacy and security of health information. When PHI features are enabled, we comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and applicable state privacy laws.
2. PHI We May Handle
When PHI features are activated, referrals may include:
- Patient name, date of birth, and contact information
- Medical record numbers (MRN)
- Insurance identification numbers
- Diagnosis codes (ICD-10)
- Clinical notes and referral documentation
- Uploaded clinical documents
All PHI fields are encrypted at the application layer using AES-256 encryption. Access to PHI is logged in our audit system.
3. How We Protect PHI
- Application-layer encryption (AES-256-CBC) for all PHI fields
- Comprehensive audit logging of all PHI access events
- Role-based access control — providers can only view referrals they are a party to
- Session management with automatic timeout (30 minutes inactivity, 8 hours max)
- Encrypted file storage for clinical documents
- Business Associate Agreements (BAA) with all sub-processors
4. Your Rights as a Patient
Under HIPAA, you have the right to:
- Access: Request a copy of your health information held on the Platform
- Amendment: Request correction of inaccurate health information
- Accounting: Request a list of disclosures of your health information
- Restriction: Request restrictions on certain uses of your information
- Confidential communication: Request that we communicate with you in a specific way
- Complaint: File a complaint if you believe your privacy rights have been violated
5. Breach Notification
In the event of a breach of unsecured PHI, Sanum will notify affected individuals within 60 days of discovery, as required by the HITECH Act. We will also notify the U.S. Department of Health and Human Services and, where required, the media.
6. Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with:
- Sanum Privacy Officer: privacy@sanumnetwork.com
- U.S. Department of Health and Human Services, Office for Civil Rights: www.hhs.gov/ocr/complaints
You will not be retaliated against for filing a complaint.
7. Changes to This Notice
We reserve the right to change this notice and the privacy practices described herein. Any revised notice will be posted on the Platform and will apply to all PHI we maintain.