OphthoIT
Features How It Works Team Contact
Book a Demo
Compliance

HIPAA Notice

Last updated: August 26, 2026

Important: There is no official U.S. government “HIPAA certificate.” OphthoIT designs services with HIPAA Privacy and Security Rule expectations in mind. This page explains how we handle website contact and client engagements. It is not legal advice.

1. Who this notice covers

This notice applies to visitors of ophthoit.com and to prospective or current clients of OphthoIT seeking IT services for ophthalmology and eye-care practices.

2. This website is not for patient records

Please do not send protected health information (PHI) through our public website contact form, marketing email links, or unsecured channels. That includes patient names tied to clinical details, medical record numbers, diagnoses, treatment notes, images, or insurance identifiers.

  • Use the contact form only for business and IT inquiry details (your name, practice name, phone, and high-level needs).
  • If PHI must be shared later, we will agree on an appropriate secure method and documentation (such as a Business Associate Agreement when required).

3. How OphthoIT approaches HIPAA

For client engagements, OphthoIT focuses on helping practices apply reasonable administrative, physical, and technical safeguards consistent with HIPAA expectations, such as:

  • Access controls, encryption in transit/at rest where applicable, and backup/recovery planning
  • Vendor and cloud configuration guidance for healthcare environments
  • Security monitoring and incident-response planning when included in the service scope
  • Documentation support (policies, risk discussions, BAAs) as agreed in writing

Specific safeguards depend on the statement of work, tools in use, and your practice’s own covered-entity obligations.

4. Business Associate relationships

When OphthoIT creates, receives, maintains, or transmits PHI on behalf of a covered entity (or another business associate), a Business Associate Agreement (BAA) should be executed before PHI is shared. Marketing or demo conversations that do not involve PHI generally do not require PHI transfer.

5. Website data we may collect

When you contact us, we may receive business contact details you voluntarily provide (name, email, phone, practice name, and message). See our Privacy Policy for more detail. We ask that messages exclude PHI.

6. No warranty of certification status

Statements on this site about “HIPAA-aware,” “HIPAA-aligned,” or similar language describe our design approach and service focus. They do not mean OphthoIT holds a government-issued HIPAA license or a third-party seal unless we separately document that attestation for a specific engagement.

7. Contact

Questions about this notice:

  • Email: contact@ophthoit.com
  • Phone: 917-892-0222

← Back to homepage · Privacy Policy · Terms of Service

© 2025 OphthoIT. All rights reserved.

Privacy Policy Terms of Service HIPAA Notice