1. Our role under HIPAA
When Alli Health performs care-management support services on behalf of a healthcare practice, Alli acts as a Business Associate as defined by the Health Insurance Portability and Accountability Act (HIPAA). The practice remains the Covered Entity and the steward of its patients' relationships and clinical decisions.
2. Business Associate Agreements
Alli enters into a written Business Associate Agreement (BAA) with every practice customer before receiving or processing any protected health information (PHI). Our BAA addresses permitted uses and disclosures, safeguards, subcontractor flow-down, breach notification, and PHI return or destruction at termination. Practices can request our standard BAA at hello@allihealth.ai.
3. How we handle PHI
- Minimum necessary: we use and disclose PHI only as needed to perform contracted services: patient enrollment and consent, monthly check-ins, documentation, escalation routing, and billing-support reporting.
- Isolation: each practice's data is maintained in a logically separate instance; PHI is not pooled across practices or used to train models.
- Encryption: PHI is encrypted in transit and at rest.
- Access controls: access is limited to personnel who need it to deliver services, under role-based permissions and audit logging.
- Subcontractors: vendors that touch PHI (e.g., telephony, messaging, hosting, AI processing) are engaged under BAAs with equivalent obligations. A current list of subprocessors is available to practice customers on request.
4. Breach notification
In the event of a breach of unsecured PHI, Alli will notify affected practice customers without unreasonable delay and within the timeframes required by the HITECH Act and our BAAs, and will cooperate fully in any required notifications and remediation.
5. Security program
Alli maintains an information-security program aligned to the HIPAA Security Rule, including risk assessments, workforce training, incident response procedures, and vendor review. A SOC 2 examination is in progress.
6. For patients
If you are a patient enrolled in an APCM program supported by Alli, your healthcare practice's Notice of Privacy Practices governs how your health information is used and describes your rights (including access, amendment, and accounting of disclosures). Please direct privacy requests to your practice; we support practices in fulfilling them.
7. Contact
Privacy and security questions: hello@allihealth.ai.