HIPAA & Protected Health Information
Our platform is designed to operate outside the scope of HIPAA.
The short version
Tendral's platform is for healthcare market research. We do not collect, process, or store Protected Health Information (PHI) as defined by HIPAA, and we are not a HIPAA covered entity or business associate. Because we do not handle PHI, our platform operates outside the scope of HIPAA.
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards to protect patients' medical records and other personal health information. HIPAA applies to covered entities (healthcare providers, health plans, and healthcare clearinghouses) and their business associates who handle Protected Health Information (PHI).
What We Collect — and What We Don't
Our platform collects and processes:
- Professional credentials and identity-verification data
- Survey responses reflecting clinical opinions and market research
- Aggregated, de-identified research insights
- Account and payment information
We do not collect: patient names, medical record numbers, individual patient health information, or any other PHI. Surveys are designed to gather professional opinions, not patient data.
Business Associate Agreements (BAAs)
Because Tendral does not handle PHI, we do not enter into Business Associate Agreements. If your organization has a specific compliance question, we're happy to discuss how our platform keeps research activities separate from patient care.
Questions?
For questions about how we handle data, see our Privacy Policy and Security pages, or contact us:
Email: security@tendralhealth.com