DrLeadGen

HIPAA Compliance Notice

Last updated: July 1, 2026

DrLeadGen operates as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA) when providing services to covered healthcare entities.

Business Associate Agreement

Before DrLeadGen accesses, transmits, or processes any Protected Health Information (PHI) on behalf of your practice, we will execute a Business Associate Agreement (BAA) with your organization. No PHI is handled without a signed BAA in place.

What Constitutes PHI

Protected Health Information includes any information that identifies a patient and relates to their health condition, healthcare services received, or payment for healthcare. This includes names, contact details, appointment records, and procedure information when linked to an identifiable individual.

How We Protect PHI

  • PHI is encrypted in transit (TLS 1.2+) and at rest (AES-256)
  • Access to PHI is restricted to authorized personnel only, on a need-to-know basis
  • We maintain audit logs of all PHI access
  • Staff who handle PHI receive HIPAA training
  • We have incident response procedures for any potential breach

Breach Notification

In the event of a breach of unsecured PHI, DrLeadGen will notify your practice in accordance with HIPAA's Breach Notification Rule, including the content and timing requirements of 45 CFR §164.410.

Permitted Uses and Disclosures

DrLeadGen uses PHI only as permitted by our BAA and HIPAA regulations — specifically to perform services on your behalf, as required by law, or as otherwise authorized by you in writing.

Contact

HIPAA compliance questions: hipaa@drleadgen.com