Updated on March 18, 2025
Updated on March 18, 2025
HIPAA
HIPAA is a US healthcare law framework that governs the use, disclosure, and safeguarding of protected health information (PHI). The HITECH Act expanded HIPAA in 2009 to promote electronic health records and related health IT.
For QTIS AI CORPORATION, the practical relevance is that HIPAA applies whenever the company creates, receives, maintains, transmits, or accesses PHI as part of services delivered to covered entities or on their behalf. If QTIS AI CORPORATION uses a cloud provider to handle PHI, that provider may also be treated as a business associate depending on the service arrangement.
HIPAA is a US healthcare law framework that governs the use, disclosure, and safeguarding of protected health information (PHI). The HITECH Act expanded HIPAA in 2009 to promote electronic health records and related health IT.
For QTIS AI CORPORATION, the practical relevance is that HIPAA applies whenever the company creates, receives, maintains, transmits, or accesses PHI as part of services delivered to covered entities or on their behalf. If QTIS AI CORPORATION uses a cloud provider to handle PHI, that provider may also be treated as a business associate depending on the service arrangement.
Who HIPAA Covers
HIPAA applies to covered entities such as healthcare providers, hospitals, and health insurers, as well as business associates that perform services involving PHI. A cloud service provider can become a business associate when it handles PHI for a covered entity or for another business associate.
For QTIS AI CORPORATION, this means the company should assume HIPAA obligations are triggered whenever it processes PHI for healthcare customers, and that downstream vendors handling PHI may also need to meet business associate requirements.
HIPAA applies to covered entities such as healthcare providers, hospitals, and health insurers, as well as business associates that perform services involving PHI. A cloud service provider can become a business associate when it handles PHI for a covered entity or for another business associate.
For QTIS AI CORPORATION, this means the company should assume HIPAA obligations are triggered whenever it processes PHI for healthcare customers, and that downstream vendors handling PHI may also need to meet business associate requirements.
Core HIPAA Rules
The main HIPAA and HITECH components described in the source text are:
Privacy Rule: Protects the privacy of PHI, restricts use and disclosure without authorization, and gives patients rights to inspect and request corrections to their records.
Security Rule: Requires administrative, technical, and physical safeguards for electronic PHI.
Breach Notification Rule: Requires notification when unsecured PHI is breached.
For QTIS AI CORPORATION, these rules translate into operational requirements for access control, security governance, auditability, incident response, and customer-facing privacy procedures.
The main HIPAA and HITECH components described in the source text are:
Privacy Rule: Protects the privacy of PHI, restricts use and disclosure without authorization, and gives patients rights to inspect and request corrections to their records.
Security Rule: Requires administrative, technical, and physical safeguards for electronic PHI.
Breach Notification Rule: Requires notification when unsecured PHI is breached.
For QTIS AI CORPORATION, these rules translate into operational requirements for access control, security governance, auditability, incident response, and customer-facing privacy procedures.
Business Associate Agreements
HIPAA requires covered entities and business associates to sign a Business Associate Agreement (BAA). A BAA defines permitted PHI uses and disclosures and sets contractual obligations for safeguarding PHI.
For QTIS AI CORPORATION, a BAA is a key contractual control whenever the company acts as a business associate for customers. The same review should extend to subcontractors and cloud vendors that may touch PHI.
Vendors and HIPAA
The source text explains that there is no formal HHS certification program for cloud providers to prove HIPAA compliance directly. Instead, HIPAA and HITECH requirements are commonly mapped to recognized frameworks such as NIST SP 800-66, NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001, FedRAMP, and CSA Cloud Controls Matrix.
Microsoft states that Azure and Azure Government maintain attestations and certifications including FedRAMP High, CSA STAR Certification, CSA STAR Attestation, NIST CSF alignment, and ISO/IEC 27001 certification. Microsoft also offers a HIPAA BAA for in-scope Azure services and states that it implements physical, technical, and administrative safeguards relevant to its role as a business associate.
For QTIS AI CORPORATION, this means Azure can support a HIPAA-aligned environment, but Azure compliance features do not by themselves make QTIS AI CORPORATION compliant. The company remains responsible for its own configuration, access management, application controls, data handling, and overall compliance program.
The source text explains that there is no formal HHS certification program for cloud providers to prove HIPAA compliance directly. Instead, HIPAA and HITECH requirements are commonly mapped to recognized frameworks such as NIST SP 800-66, NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001, FedRAMP, and CSA Cloud Controls Matrix.
Microsoft states that Azure and Azure Government maintain attestations and certifications including FedRAMP High, CSA STAR Certification, CSA STAR Attestation, NIST CSF alignment, and ISO/IEC 27001 certification. Microsoft also offers a HIPAA BAA for in-scope Azure services and states that it implements physical, technical, and administrative safeguards relevant to its role as a business associate.
For QTIS AI CORPORATION, this means Azure can support a HIPAA-aligned environment, but Azure compliance features do not by themselves make QTIS AI CORPORATION compliant. The company remains responsible for its own configuration, access management, application controls, data handling, and overall compliance program.
Access Control, Audit Trails, and Accountability
Our platforms provide flexible role-based access control so that organisations can define fine-grained permissions at the user, team, and project level. This allows controllers to ensure that only appropriate personnel can view or modify clinical and trial data.
Comprehensive audit trails record key actions in the system, including data creation, changes, exports, and administrative operations. These logs support accountability, internal review, incident investigation, and regulatory reporting when needed.
Our platforms provide flexible role-based access control so that organisations can define fine-grained permissions at the user, team, and project level. This allows controllers to ensure that only appropriate personnel can view or modify clinical and trial data.
Comprehensive audit trails record key actions in the system, including data creation, changes, exports, and administrative operations. These logs support accountability, internal review, incident investigation, and regulatory reporting when needed.
Changes to this policy
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
We may update this policy to reflect changes in our services or the law. We will notify you of significant changes.
Contact us
If you have questions or concerns, please email us at compliance@qtis.ai
If you have questions or concerns, please email us at support@q