HIPAA & Business Associate Commitment
We work with surgeons and medical practices every day, so protecting patient information is part of the job — not an afterthought. This page explains how Medical Advertising Agency treats protected health information (PHI) and how we structure our relationships with the practices we serve under HIPAA.
When we are a Business Associate
Most of our work — building a website, producing patient testimonial videos, running ads, managing reviews — can put us in contact with protected health information. When that is the case, HIPAA treats us as a “Business Associate” of your practice.
Before any work begins that involves PHI, we sign a Business Associate Agreement (BAA) with your practice. The BAA defines how we may use and disclose PHI, the safeguards we maintain, and our obligations if anything goes wrong.
How we handle patient information
We use and disclose PHI only to perform the services your practice has engaged us for, and only as your BAA permits. We do not sell PHI and we do not use it for any purpose of our own.
Patient testimonials and before-and-after imagery are only published with the patient’s written authorization, obtained and retained by the practice. We will not publish a patient’s story or images without that authorization in place.
Safeguards
We maintain administrative, physical, and technical safeguards appropriate to the information we handle — including access controls, encryption in transit, limiting access to staff who need it, and secure disposal of information we no longer need.
We keep the amount of PHI we touch to the minimum necessary to do the work, and we prefer de-identified material whenever it will serve the same purpose.
Subcontractors
Where we rely on vendors that may handle PHI on our behalf — for example secure hosting or video platforms — we put appropriate agreements in place so that those vendors are bound by protections at least as strict as our own.
Breach notification
If we ever discover a breach of unsecured PHI, we will notify the affected practice without unreasonable delay and cooperate fully so the practice can meet its notification obligations under HIPAA.
What we ask of your practice
Please share only the information we need for the work at hand, and use the secure channels we set up together. Do not send PHI through this website’s contact forms — those are not a secure channel for patient information.
Request a BAA or ask a question
If your practice needs a Business Associate Agreement in place before we begin, or you have a question about how we handle PHI, text us at 941-400-0104 or email info@medicaladvertising.agency. Our office is at 759 N Lime Ave, Sarasota, FL.