MedMatch follows the Health and Human Rights (HHS) office of Civil Rights (OCR) recommendations for staying HIPAA compliant by performing the following quarterly audits:
- Security Risk Assessment
- Privacy Standards Audit
- HITECH Subtitle D Privacy Audit
- Security Standards Audit
- Asset & Device Audit
- Physical Site Audit
Any gaps or deficiencies are documented with appropriate remediation steps. MedMatch has policies & procedures in place for annual HIPAA privacy, security, and breach notification rules. Security and privacy. As a member of the MedMatch network, you agree to our terms and conditions of use which extends to, but not limited, to the terms of a business associate agreement.