Is ClinicMonk™ HIPAA Compliant?
Yes, ClinicMonk™ is HIPAA compliant.
Protecting client information is incredibly important in healthcare, and we know many practices want to understand how ClinicMonk™ approaches privacy, security, and HIPAA-conscious workflows.
ClinicMonk™ uses secure infrastructure that supports HIPAA compliance and meets privacy standards in the U.S.
We guide you through setting up your account in a way that aligns with HIPAA, including consent-based communication, secure data handling, and proper use of email and SMS.
ClinicMonk™ is not designed for storing clinical notes or sensitive health records. Your EHR (like Jane App) remains the place for documentation, while ClinicMonk™ is used for lead tracking, follow-up, and client communication.
That said, HIPAA compliance is not determined by software alone. Compliance is a shared responsibility between the platform and the healthcare practice using it.
This guide is designed to help explain:
- what HIPAA is
- how ClinicMonk™ supports healthcare practices
- what safeguards are in place
- practical steps to help clinics get started with or double check policies and procedures
This information is not a legal interpretation of the law and is not binding on the Office for Civil Rights of the U.S. Department of Health and Human Services. This information is not intended to nor should it ever replace formal legal counsel.
What Is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. law that establishes standards for protecting Protected Health Information (PHI).
PHI can include information such as:
- names
- phone numbers
- appointment details
- health information
- intake information
- treatment records
- other identifiable healthcare data
HIPAA applies to healthcare organizations and certain vendors that store, process, or transmit PHI electronically.
As healthcare practices increasingly move toward cloud-based systems, electronic scheduling, online forms, automations, and digital communication, maintaining privacy and security standards becomes an important part of running a modern practice.
How ClinicMonk™ Supports HIPAA-Conscious Workflows
ClinicMonk™ is designed specifically for healthcare practices and includes features intended to help clinics operate more securely and efficiently.
Secure User Access
ClinicMonk™ allows practices to control who has access to information within the platform through user roles and permissions.
This helps clinics:
- limit unnecessary access to sensitive information
- organize team responsibilities
- support internal privacy procedures.
We recommend each staff member use their own unique login credentials and avoid sharing accounts.
Multi-Factor Authentication (MFA)
To help improve account security, ClinicMonk™ strongly encourages the use of Multi-Factor Authentication (MFA) wherever available.
MFA adds an additional layer of protection by requiring users to verify their identity using a second method beyond just a password. This can help reduce the risk of unauthorized access to sensitive information.
We recommend enabling MFA for all staff members who access ClinicMonk™.
Automation & Appointment Reminders
Many practices use ClinicMonk™ automations to:
- confirm appointments
- send reminder messages
- follow up on inquiries
- and reduce missed appointments
Practices should carefully review the content included in automated messages and avoid including unnecessary sensitive health information.
Encryption & Data Protection
ClinicMonk™ uses infrastructure designed to support secure data handling practices, including encryption technologies intended to help protect information both during transmission and while stored.
Security measures may include:
- encryption in transit
- encryption at rest
- secure cloud hosting environments
- and ongoing infrastructure protections
Encryption helps reduce the risk of unauthorized access to sensitive information.
HIPAA & Text Messaging
Text messaging can be an incredibly helpful communication tool for healthcare practices, but it is important to understand its limitations.
Standard SMS messages are not always fully secure and may carry some privacy risks depending on how they are used.
For this reason, many practices:
- avoid including detailed health information in text messages
- use SMS primarily for logistical communication
- obtain appropriate client consent for text communication
HIPAA & Email Communication
Email communication should also be used thoughtfully within healthcare settings.
Practices should consider:
- what information is appropriate to send through email
- whether client consent is required
- whether internal policies align with HIPAA and local privacy regulations.
Many practices choose to avoid sending highly sensitive clinical information through standard email workflows.
Third-Party Integrations
Healthcare practices often connect multiple systems together to support their operations.
ClinicMonk™ may integrate with:
- calendars
- phone systems
- email providers
- practice management software
- payment processors
- other third-party tools
Practices are responsible for reviewing the privacy and security standards of any third-party services they choose to use alongside ClinicMonk™.
Security Rule
HIPAA’s Security Rule focuses on protecting electronically stored and transmitted Protected Health Information (PHI). The Security Rule outlines safeguards that organizations handling electronic PHI should have in place to help protect the privacy, security, and integrity of healthcare data.
These safeguards generally fall into 3 categories:
- Administrative Safeguards
- Physical Safeguards
- Technical Safeguards
Below is an overview of how ClinicMonk™ approaches each of these areas.
Administrative Safeguards
Administrative safeguards refer to the policies, procedures, and operational practices that help organizations manage and protect sensitive healthcare information.
This may include:
- staff training
- access management
- internal privacy policies
- password procedures
- user permissions
- processes surrounding how PHI is handled.
Under HIPAA, healthcare organizations are also responsible for ensuring they have appropriate agreements in place with vendors or service providers that may access, store, transmit, or process Protected Health Information on their behalf. These vendors may be considered Business Associates under HIPAA.
ClinicMonk™’s Administrative Approach
ClinicMonk™ is designed with healthcare workflows in mind, and we take privacy and security seriously.
Access to client accounts is limited and controlled internally. Authorized ClinicMonk™ personnel may access customer accounts and associated data when necessary to provide technical support, onboarding assistance, troubleshooting, security monitoring, investigate suspected misuse or violations of the Terms, perform platform-related services, comply with legal obligations, facilitate approved integrations, or otherwise fulfill ClinicMonk's obligations under its Terms of Service.
We also encourage practices using ClinicMonk™ to:
- create individual staff accounts
- avoid shared logins
- regularly review team permissions
- implement strong password policies internally
Where appropriate, team members handling sensitive information are HIPAA trained and expected to follow confidentiality and privacy procedures designed to support responsible data handling practices.
In addition, practices remain responsible for ensuring their own staff receive proper HIPAA and privacy training and for implementing their own internal privacy policies and procedures.
Physical Safeguards
Physical safeguards focus on protecting the physical systems, servers, and facilities where electronic data is stored and processed.
This includes measures designed to prevent unauthorized physical access to systems containing Protected Health Information.
ClinicMonk™’s Physical Approach
When it comes to the physical location of your data, ClinicMonk™ does not store any product systems or patient records within its physical offices. Instead, we outsource our hosting infrastructure to industry-leading cloud providers—specifically Google Cloud Platform (GCP) and Amazon Web Services (AWS)—with all server infrastructure located within secure data centers in the United States.
These state-of-the-art facilities enforce the strictest physical, environmental, and infrastructure security controls, including:
- Controlled Facility Access & Surveillance: Strict biometric authentication, 24/7 continuous security monitoring, and surveillance systems to eliminate unauthorized physical access.
- Environmental & Power Redundancy: Advanced HVAC services, automated climate controls, and fully redundant power and network infrastructure to maximize platform uptime and ensure business continuity.
- Rigorous Industry Certifications: The business continuity, physical security, and disaster recovery plans of our infrastructure providers are independently validated. All of our data center facilities are SOC 2 Type 2 audited and compliant and maintain ISO 27001 certifications.
By leveraging Google’s and AWS’s heavily audited security programs, we ensure your clinic's data benefits from world-class physical protections that meet or exceed industry standards.
Technical Safeguards
Technical safeguards focus on the technology, systems, and controls used to protect electronic Protected Health Information during storage and transmission.
This includes:
- encryption
- access controls
- user authentication
- audit logging
- system monitoring
ClinicMonk™’s Technical Approach
ClinicMonk™ includes a number of technical safeguards intended to help healthcare practices protect sensitive information and support HIPAA-conscious workflows.
Information transmitted through ClinicMonk™ is protected using bank-grade encryption protocols (TLS 1.2 or 1.3 with 2,048-bit keys) to secure data while in transit between users and the platform. Furthermore, our data storage environments automatically encrypt all data at rest using 256-bit Advanced Encryption Standard (AES-256) before it is written to disk.
ClinicMonk™ relies on modern cloud infrastructure providers and security protections that may include:
- Web Application Firewall Protections: Actively filtering and inspecting all incoming traffic aligned with industry-standard OWASP best practices.
- Automated Configuration Management: Infrastructure baselines are strictly automated; any server configuration drift is automatically detected and overwritten back to compliance within 30 minutes.
- Continuous Infrastructure Monitoring: 24/7 automated monitoring and central security logging to track user access and immediately alert engineers to anomalies.
- Network-Level Segmentation: Advanced perimeter defenses and data isolation methods designed to keep your clinic's database securely separated.
Because ClinicMonk™ includes communication and automation tools such as appointment reminders, follow-up workflows, intake forms, and SMS/email communication, practices are encouraged to carefully review their workflows and avoid including unnecessary Protected Health Information (PHI) in automated messages whenever possible.
Healthcare practices remain responsible for configuring their accounts appropriately, managing staff access, maintaining internal privacy procedures, and ensuring their workflows align with HIPAA requirements and applicable regulations.
Business Associate Agreements (BAAs)
Under HIPAA, vendors that handle Protected Health Information (PHI) on behalf of healthcare organizations may be considered Business Associates.
ClinicMonk™ provides a Business Associate Agreement (BAA) for practices using the platform. The BAA outlines the responsibilities of both ClinicMonk™ and the healthcare practice regarding the handling and protection of Protected Health Information in connection with the services provided through the platform.
Steps Practices Can Take to Help Remain HIPAA-Conscious
This is not an exhaustive list of steps for compliance. It merely offers a general summary of the recommendations of the U.S. Department of Health and Human Services. These steps and this Guide document as a whole are not intended to be nor should they be considered legal advice.
HIPAA compliance is not achieved through software alone. Internal clinic procedures play an important role in protecting client information.
Below are some best practices healthcare organizations may consider implementing:
-
Create clinic-wide privacy procedures.
Every healthcare practice should have clear privacy policies and procedures in place regarding how Protected Health Information (PHI) is collected, accessed, used, stored, and disclosed.
We recommend assigning a Privacy Officer or designated team member responsible for:
- overseeing privacy procedures
- handling privacy-related concerns
- training staff on HIPAA-conscious workflows
- ensuring team members understand how PHI should be handled within ClinicMonk™ and other systems used by the practice
Practices should also:
- document internal privacy policies
- train staff regularly
- maintain processes for tracking disclosures when required
- follow the principle of sharing the minimum necessary information
-
Obtain consent to collect, use and disclose PHI.
Healthcare practices should have clear processes in place for obtaining consent related to the collection, use, and disclosure of Protected Health Information.
This may include:
- Digital forms (such as your website contact forms, online booking forms, and lead magnet forms)
- Communication consent checkboxes to capture explicit user authorization
- Consent text tailored to your specific jurisdiction's rules for SMS and email communications
- Internal procedures outlining exactly when and how information may or may not be disclosed by your staff
ClinicMonk™ allows practices to automate parts of the intake and communication process, but practices remain responsible for ensuring proper consent procedures are in place and documented appropriately.
-
Construct an emergency plan.
Healthcare organizations should have contingency plans in place to help protect access to important information during emergencies or unexpected disruptions.
This may include planning for:
- internet outages
- device failures
- staff emergencies
- security incidents
- temporary disruptions to software systems
Practices should also have internal procedures for responding to potential privacy or security incidents, including determining when notification requirements may apply under HIPAA or state regulations.
-
Secure your devices, website and network.
Healthcare practices should take steps to protect all devices, systems, and networks that may access Protected Health Information.
This includes:
- using secure passwords
- requiring unique staff logins
- enabling Multi-Factor Authentication (MFA) where available
- setting automatic device timeouts
- encrypting data transmissions
- maintaining secure internet and Wi-Fi networks
Practices should also train staff on proper handling of electronic PHI and ensure that only authorized individuals have access to sensitive information.
ClinicMonk™ supports role-based permissions, audit logs, user authentication controls, and secure account access to help practices manage access to information more securely.
-
Weigh your options for storing PHI.
Healthcare practices should carefully evaluate how and where Protected Health Information is stored.
Some practices may use:
- physical records
- local servers
- cloud-based systems
- a combination of storage methods.
Many healthcare organizations choose cloud-based platforms like ClinicMonk™ because they allow practices to centralize workflows, manage communications more efficiently, and implement role-based access controls.
When evaluating any software platform, practices should consider:
- encryption standards
- audit logging capabilities
- user permission controls
- infrastructure security
- backup procedures
- the vendor’s approach to privacy and security.
-
Sign a Business Associate Agreement (BAA) with software vendors.
HIPAA requires a written contract between practices and any other entity handling PHI. For this contract, HIPAA defines two types of organizations:
- Covered Entity: This is the organization recording the data. Typically this means health clinics and practitioners - basically anyone treating patients or seeing clients.
- Business Associate: The organization that is helping store and process data on behalf of the above “Covered Entity.”
ClinicMonk™ provides a Business Associate Agreement (BAA) for practices using the platform. Practices should also review any other third-party vendors or integrations they use to determine whether additional agreements may be required.
-
Consider your state laws.
In addition to HIPAA, healthcare practices may also be subject to state-specific privacy and healthcare regulations.
Some states may impose additional requirements related to:
- patient consent
- data retention
- breach notification
- telehealth
- electronic communications
Practices should ensure they understand the laws and regulations that apply within their jurisdiction and update their policies accordingly.
-
Check with your regulating body.
Healthcare professionals should also consult their licensing boards, colleges, or regulatory organizations for any additional privacy guidance or professional standards that may apply to their discipline.
Some regulatory bodies may recommend additional best practices regarding:
- electronic communication
- record keeping
- informed consent
- telehealth workflows
-
Stay current.
Privacy and healthcare regulations continue to evolve alongside technology.
Healthcare practices should regularly review and update their:
- privacy procedures
- staff training
- security settings
- communication workflows
- and software configurations
We recommend practices periodically review their ClinicMonk™ setup, automations, permissions, and integrations to help ensure they continue aligning with current privacy and security best practices.
Shared Responsibility
While ClinicMonk™ is designed to support healthcare practices with privacy-conscious systems and workflows, HIPAA compliance is ultimately a shared responsibility between the platform and the healthcare organization using it.
Healthcare practices remain responsible for:
- determining what information is appropriate to communicate electronically
- obtaining any required client consents
- training staff
- managing internal privacy procedures
- ensuring their workflows comply with applicable laws and regulations.
Important Disclaimer
This guide is provided for educational and informational purposes only and should not be considered legal, compliance, or regulatory advice.
ClinicMonk™ is designed to support healthcare practices with privacy-conscious workflows and operational systems, but no software platform alone can guarantee HIPAA compliance.
Each healthcare organization is responsible for evaluating its own compliance obligations and implementing appropriate policies, procedures, and safeguards.
We encourage all practices to consult qualified legal or compliance professionals regarding their specific HIPAA requirements.
Questions?
If you have questions about ClinicMonk™ and how it supports healthcare practices, our team would be happy to help.
Visit ClinicMonk™ or email hello@clinicmonk.com to learn more.