LEGAL + TRUST

HIPAA and Health Information Statement

HIPAA applicability depends on the parties, data, and activities involved. CLR RX is being structured to support covered entities and business associates, but a product screen or policy page cannot make an organization compliant.

Last updated August 12, 2026 · Draft for counsel and operational review before commercial launch.
01

Role

A clinic may be a HIPAA covered entity when it conducts covered electronic transactions. CLR RX may act as a business associate when it creates, receives, maintains, or transmits protected health information on behalf of a covered entity or another business associate.

02

Business associate agreements

Before CLR RX processes protected health information as a business associate, the parties must execute a written agreement defining permitted and required uses, safeguards, reporting, subcontractor obligations, individual-rights support, return or destruction, and other required terms.

03

Safeguards

The target program addresses administrative, physical, and technical safeguards for confidentiality, integrity, and availability, including risk analysis, access controls, audit controls, integrity, authentication, transmission security, contingency planning, and workforce procedures.

04

Minimum necessary

Role and workflow design should limit uses, disclosures, and requests to the minimum necessary when that standard applies. Treatment disclosures and other exceptions are governed by applicable law and customer policy.

05

Individual rights

The clinic or other covered entity remains responsible for notices and for responding to access, amendment, restriction, accounting, and complaint rights. CLR RX may support those workflows under contract.

06

No certification claim

HHS does not issue a general HIPAA-compliance certification for software. CLR RX will not use HIPAA-compliant as a marketing guarantee without a defined, implemented, documented, and reviewed production control environment.

Legal review required

This working policy framework is designed to make the company's intended position visible and actionable. It should be finalized against the actual legal entity, contracts, data flows, vendors, states, insurance model, products, and production controls before reliance or launch.