Occupancy Pilot
  • Features
  • Templates
  • Pricing
Log in Get Started

HIPAA Compliance

Last updated: February 1, 2026

Our Commitment to HIPAA

Occupancy Pilot is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health Act (HITECH).

As a Business Associate serving senior living communities, we understand the sensitive nature of health-related information and have implemented comprehensive safeguards to ensure compliance with all applicable regulations.

HIPAA Overview

HIPAA establishes national standards to protect sensitive patient health information from being disclosed without the patient's consent or knowledge. The law includes several key rules:

  • Privacy Rule: Establishes standards for protecting individuals' medical records and personal health information
  • Security Rule: Sets national standards for securing electronic protected health information (ePHI)
  • Breach Notification Rule: Requires notification following a breach of unsecured PHI
  • Enforcement Rule: Contains provisions relating to compliance and investigations

Business Associate Agreement

Occupancy Pilot enters into Business Associate Agreements (BAAs) with all covered entities that use our platform to process PHI. Our BAA:

  • Establishes the permitted and required uses of PHI
  • Provides that we will not use or further disclose PHI other than as permitted or required by the agreement or as required by law
  • Requires appropriate safeguards to prevent unauthorized use or disclosure
  • Requires reporting of any unauthorized use or disclosure
  • Ensures our subcontractors agree to the same restrictions
  • Makes our internal practices, books, and records available to the Secretary of HHS
  • Returns or destroys all PHI at the termination of the agreement

To request a BAA, please contact us at [email protected].

Administrative Safeguards

We have implemented comprehensive administrative safeguards to protect PHI:

Security Management Process

  • Regular risk assessments to identify potential vulnerabilities
  • Documented security policies and procedures
  • Sanctions for policy violations
  • Regular review and updates of security measures

Workforce Security

  • Background checks for all employees with access to PHI
  • Role-based access controls based on job function
  • Immediate access termination upon employment end
  • Regular access reviews and audits

Security Training

  • Mandatory HIPAA training for all employees
  • Annual refresher training and updates
  • Security awareness programs
  • Phishing simulation and testing

Incident Response

  • Documented incident response procedures
  • 24/7 security monitoring and alerting
  • Breach investigation and reporting protocols
  • Regular incident response drills

Physical Safeguards

Our physical security measures include:

Facility Access Controls

  • Data centers with 24/7 security personnel
  • Biometric access controls
  • Video surveillance and monitoring
  • Visitor management and escort policies

Workstation Security

  • Encrypted workstations and devices
  • Automatic screen locks
  • Clean desk policies
  • Secure disposal of media and documents

Device and Media Controls

  • Inventory tracking of all devices
  • Secure data wiping procedures
  • Encryption of portable devices
  • Physical destruction of retired media

Technical Safeguards

We employ industry-leading technical safeguards:

Access Controls

  • Unique user identification for all users
  • Multi-factor authentication (MFA)
  • Automatic session timeout
  • Role-based access permissions

Audit Controls

  • Comprehensive activity logging
  • Real-time monitoring and alerting
  • Log retention for 6+ years
  • Regular audit log reviews

Integrity Controls

  • Data validation and checksums
  • Version control and change tracking
  • Automated backup verification
  • Data integrity monitoring

Transmission Security

  • TLS 1.3 encryption for all data in transit
  • AES-256 encryption for data at rest
  • Secure API endpoints
  • Certificate management and rotation

Data Centers and Infrastructure

Occupancy Pilot utilizes HIPAA-compliant cloud infrastructure:

  • SOC 2 Type II certified data centers
  • ISO 27001 certified facilities
  • HIPAA-eligible cloud services
  • Geographically distributed for redundancy
  • 99.99% uptime SLA
  • Automatic failover capabilities

Breach Notification

In the event of a breach of unsecured PHI, Occupancy Pilot will:

  • Notify affected covered entities within 24 hours of discovery
  • Provide detailed information about the nature of the breach
  • Identify the types of PHI involved
  • Describe steps taken to investigate and mitigate
  • Provide recommendations for protecting affected individuals
  • Cooperate fully with breach notification requirements

We maintain cyber liability insurance and have established relationships with breach response specialists to ensure rapid and effective incident response.

Subcontractor Management

Occupancy Pilot ensures all subcontractors with access to PHI:

  • Enter into Business Associate Agreements
  • Demonstrate HIPAA compliance capabilities
  • Undergo security assessments
  • Maintain appropriate insurance coverage
  • Report security incidents promptly

Patient Rights

We support covered entities in honoring patient rights under HIPAA:

  • Right to Access: Patients can request copies of their PHI
  • Right to Amend: Patients can request corrections to their PHI
  • Right to Accounting: Patients can request a list of disclosures
  • Right to Restrict: Patients can request restrictions on use
  • Right to Confidential Communications: Patients can request alternative communication methods

Compliance Certifications

Occupancy Pilot maintains the following certifications and attestations:

SOC 2 Type II Annual audit by independent third party
HIPAA Annual compliance assessment
ISO 27001 Information security management

Security Best Practices for Customers

To maintain HIPAA compliance while using Occupancy Pilot, we recommend:

  • Enable multi-factor authentication for all user accounts
  • Use strong, unique passwords
  • Regularly review user access and permissions
  • Train staff on HIPAA requirements and security awareness
  • Report any suspected security incidents immediately
  • Keep your contact information up to date for security notifications
  • Review and update your forms to collect only necessary PHI

Regular Audits and Assessments

Occupancy Pilot conducts regular security assessments:

  • Annual third-party penetration testing
  • Quarterly vulnerability scans
  • Continuous automated security monitoring
  • Annual HIPAA compliance audits
  • Regular policy and procedure reviews

Updates to This Policy

We may update this HIPAA Compliance statement periodically to reflect changes in our practices, technology, legal requirements, and other factors. We will notify customers of material changes and post updates on this page.

Contact Our Compliance Team

For questions about our HIPAA compliance program, to request a BAA, or to report a security concern:

Occupancy Pilot Compliance Team

Email: [email protected]

Phone: 1-800-555-1234 (Option 3)

Address: 123 Innovation Way, Austin, TX 78701

For urgent security matters, please call our 24/7 security hotline: 1-800-555-9999

Occupancy Pilot

The occupancy growth platform for senior living. Attribution-powered forms, quizzes, and workflows that show exactly what drives move-ins.

Product

  • Features
  • Templates
  • Pricing
  • Dashboard

Company

  • About
  • Blog
  • Contact
  • Careers

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • HIPAA Compliance

© 2026 Occupancy Pilot. All rights reserved.