This HIPAA Privacy Policy explains how Bloo, Inc. ("we", "us", or "Blue") protects the privacy and security of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations. This policy applies to our website www.Blue.cc and our B2B SaaS platform when used to handle PHI.
Blue acts as a Business Associate to Covered Entities when our B2B SaaS platform is used to handle PHI. We are committed to complying with HIPAA regulations in this capacity.
As a Business Associate, we may handle various types of PHI, including but not limited to:
We will only use or disclose PHI as permitted by our Business Associate Agreement with the Covered Entity and in compliance with HIPAA regulations. This may include:
We will not use or disclose PHI for marketing purposes or sell PHI unless explicitly authorized by the Covered Entity and the individual.
We implement robust security measures to protect PHI, including:
All our employees receive regular training on HIPAA compliance. Access to PHI is restricted to authorized personnel on a need-to-know basis.
We retain PHI only for as long as necessary to provide our services or as required by law. Once PHI is deleted, we keep it for 30 days before permanent deletion.
PHI is stored encrypted at rest in AWS data centers. If we transfer PHI outside the United States (e.g., to Singapore), we ensure appropriate safeguards are in place and comply with all applicable laws and regulations.
In the event of a breach of unsecured PHI, we will notify affected Covered Entities without unreasonable delay and in no case later than 60 calendar days after discovery of the breach.
We will assist Covered Entities in fulfilling their obligations to provide individuals with their rights under HIPAA, including:
Individuals should contact their healthcare provider (the Covered Entity) to exercise these rights.
As a Business Associate, Blue is committed to entering into Business Associate Agreements (BAAs) with Covered Entities as required by HIPAA. If you are a Covered Entity and wish to use our services for handling Protected Health Information (PHI), you will need to have a signed BAA with us.
To request a BAA:
Please note:
We may update this HIPAA Privacy Policy from time to time. We will notify Covered Entities of any significant changes by posting the new Privacy Policy on this page. You can find all the version controlled changes on our Gitlab Repository
If you have any questions about this HIPAA Privacy Policy, our data practices, or our BAA process, please contact our Privacy Officer:
Emanuele FAJA, CEO Email: [email protected]