Super admins and admins can enable/disable HIPAA Support. Managers and admins can mark registration form fields as ePHI/PII. Staff will not have access to this information.
The Health Insurance Portability and Accountability Act (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act) ("HIPAA"), requires Covered Entities and Business Associates to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Zoho Bookings provides certain features (as described below) to help its customers use Zoho Bookings in a HIPAA compliant manner.
HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to legal@zohocorp.com .
Zoho Bookings has provisions to protect ePHI. When collecting customer information (ePHI/PII), registration form fields can be set up for secure handling.
Below are what you can do with respect to HIPAA compliance inside Zoho Bookings:
HIPPA Support is now Enabled.
You can facilitate encryption and decryption on sensitive data for both new or existing custom registration form fields .
The data captured in registration form fields marked as ePHI/PII is
Data audits help you secure your customers' data and monitor for unexpected changes or usage trends. Zoho Bookings will record the audit logs–i.e., information about every addition, update, and deletion made to customer database records–in the backend for a duration of up to 1 year. The audit log can be shared with you only upon request.
Drop in an email to support@zohobookings.com, if you'd like to access audit logs.
Note: HIPAA support can be invoked only on guest user fields and on SingleLine, CheckBox, DropDown, Email, RadioButton, and Date custom field types only. HIPAA support cannot be invoked on default fields (Name, Email, and Contact Number) and on custom MultiLine field types, as of now.
To mark fields as ePHI/PII:
Check Mark as ePHI/PII to denote that the field (Blood Pressure, in this case) would contain sensitive information and click Save.
The selected field is marked as ePHI/PII.
HIPAA support can be invoked on more than one field. However, when you try to mark more than one field as ePHI/PII, you might receive an error message like the below.
This is because once a registration form field is marked as ePHI/PII, it takes some time in the backend to set it up. If another field is marked as ePHI/PII simultaneously while the setup for the first field is in progress, it might disrupt the setting altogether. To avoid this, it is advised to try marking the other field as ePHI/PII at a little while later.
A delete confirmation appears and informs you that the registration form fields will not be treated as sensitive. You will also not be able to mark them as ePHI/PII going forward. Click Yes, Disable HIPAA Support to proceed.
The HIPAA Support section is set to 'Disabled' now.
Existing registration form fields are no longer marked ePHI/PII. They also do not have the option to be marked as ePHI/PII.
Product/Service | Applicable Plans |
Zoho Bookings | Premium |
Note: You can view all the pricing plans for Zoho Bookings here.