Skip to main content
Built specifically for med spas, aesthetic practices and wellness clinics. Book a live demo →
DigiMEDSPA

Security & HIPAA

Healthcare Technology Built With Security at Its Core

DigiMEDSPA provides healthcare organizations with an integrated EMR and practice management platform designed to support secure clinical and administrative workflows.

Protecting patient information is fundamental to how DigiMEDSPA is designed, operated, and continuously improved.

Our platform incorporates administrative and technical safeguards designed to protect sensitive healthcare information and support our customers’ obligations under the Health Insurance Portability and Accountability Act (HIPAA).

Supporting HIPAA-Regulated Healthcare Organizations

DigiMEDSPA works with healthcare providers that may qualify as Covered Entities under HIPAA.

When DigiMEDSPA creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of an applicable healthcare customer, DigiMEDSPA operates as a Business Associate and maintains appropriate safeguards for that information.

Where required, DigiMEDSPA enters into Business Associate Agreements with applicable healthcare customers governing our handling of PHI.

Our security and privacy program is designed around protecting patient information throughout the DigiMEDSPA platform.

Business Associate Agreements

DigiMEDSPA supports healthcare organizations operating in HIPAA-regulated environments.

Where required under HIPAA, DigiMEDSPA enters into a Business Associate Agreement with healthcare customers covering DigiMEDSPA’s permitted use and protection of PHI.

DigiMEDSPA also evaluates service providers and subprocessors involved in workflows containing PHI and requires appropriate contractual and security safeguards, including Business Associate Agreements where applicable.

Data Protection

Encryption in Transit

Sensitive information transmitted between authorized users, DigiMEDSPA services, and applicable technology providers is protected using industry-standard encrypted connections.

Encryption and Protected Storage

DigiMEDSPA uses security controls designed to protect sensitive information stored within its platform and supporting infrastructure.

Controlled Data Access

Access to patient and clinic information is limited to authorized users and systems based on legitimate business and clinical requirements.

Access Controls & User Security

DigiMEDSPA provides access controls designed for healthcare environments.

Security capabilities may include:

  • Individual user accounts
  • Authentication controls
  • Role-based permissions
  • Provider and administrative access separation
  • Access restrictions based on assigned responsibilities
  • Session and account security controls
  • Administrative management of platform users

These controls help healthcare organizations limit access to patient information according to user responsibilities.

Auditability & Activity Monitoring

Healthcare organizations require visibility into how sensitive information is accessed and managed.

DigiMEDSPA maintains logging and monitoring capabilities designed to support security oversight, troubleshooting, accountability, and review of activity within applicable platform workflows.

Our security program is continuously evaluated as the platform and its capabilities evolve.

Native AI With Healthcare Privacy in Mind

DigiMEDSPA is introducing Native AI capabilities directly within the DigiMEDSPA platform.

Rather than requiring clinic users to copy patient information into separate consumer AI applications, DigiMEDSPA’s strategy is to integrate authorized AI workflows directly into the healthcare platform.

Native AI capabilities may include:

AI Scribe & Charting Assistant

Assists providers with clinical transcription, visit summaries, structured documentation, and preparation of chart notes.

AI Front Desk

Assists clinics with administrative communications, appointment-related workflows, general patient questions, call handling, and staff escalation.

AI SMS Agent

Assists authorized clinics with patient communications through DigiMEDSPA’s integrated two-way messaging environment.

Clinical Chart Assistance

Helps authorized users organize and summarize appropriate information within clinical workflows.

Human Review Remains Essential

DigiMEDSPA AI is designed to assist healthcare professionals—not replace their professional judgment.

AI-generated clinical documentation and recommendations are intended to support authorized healthcare professionals and should be reviewed for accuracy and appropriateness before becoming part of a finalized patient record or being relied upon for patient care.

Healthcare providers remain responsible for clinical decisions, diagnoses, treatment decisions, prescriptions, and other professional medical judgments.

Protecting PHI Within AI Workflows

DigiMEDSPA applies additional controls when AI workflows may involve Protected Health Information.

Our approach includes:

  • Limiting PHI processing to authorized healthcare workflows
  • Applying the minimum-necessary principle where appropriate
  • Using authorized technology providers for workflows involving PHI
  • Maintaining appropriate contractual protections with applicable subprocessors
  • Restricting access to authorized DigiMEDSPA and clinic users
  • Maintaining clinical review of AI-generated healthcare documentation
  • Avoiding the use of consumer AI accounts for authorized DigiMEDSPA clinical PHI workflows

DigiMEDSPA evaluates AI services before allowing them to process PHI within supported production healthcare workflows.

Our Approach to AI Service Providers

DigiMEDSPA evaluates third-party AI infrastructure providers based on security, privacy, data handling, contractual protections, and their suitability for healthcare workloads.

Where an AI service provider processes PHI on behalf of DigiMEDSPA, DigiMEDSPA requires the appropriate contractual framework, including a Business Associate Agreement where required, before enabling production PHI processing through that service.

DigiMEDSPA does not authorize production PHI transmission to an AI provider solely because that provider offers a general-purpose AI product.

The specific service, configuration, contractual coverage, and permitted healthcare functionality must first be evaluated.

Minimum Necessary Data

DigiMEDSPA designs healthcare workflows to limit the information transmitted or made available to external services to information reasonably necessary to perform the authorized function.

Where technically and operationally appropriate, DigiMEDSPA seeks to reduce unnecessary exposure of patient information and separate non-PHI workflows from PHI-containing workflows.

Secure Platform Architecture

Security within DigiMEDSPA extends beyond individual features.

Our platform security approach includes controls designed around:

Authentication

Helping ensure users accessing the platform are properly authorized.

Authorization

Restricting functionality and sensitive information according to user role and responsibility.

Encryption

Protecting information during transmission and within applicable storage environments.

System Monitoring

Monitoring infrastructure and application activity for security, reliability, and operational issues.

Data Protection

Maintaining controls around storage, access, backup, and handling of sensitive information.

Vendor Risk Management

Evaluating applicable technology providers that may interact with sensitive healthcare information.

Security Incident Response

DigiMEDSPA maintains procedures designed to identify, investigate, contain, document, and respond to potential security incidents affecting our systems or protected information.

When applicable, DigiMEDSPA works with affected healthcare customers in accordance with contractual requirements and applicable privacy and security obligations.

Workforce Security

Access to sensitive production systems and healthcare information is limited based on business requirements.

DigiMEDSPA maintains administrative safeguards that may include:

  • Workforce access controls
  • Confidentiality obligations
  • Security awareness procedures
  • Role-based system access
  • Access review and removal procedures
  • Internal policies governing sensitive information

Business Continuity & Data Availability

DigiMEDSPA recognizes that system availability is important to healthcare operations.

Our infrastructure and operational procedures are designed to support platform reliability, data protection, backup, recovery, and continuity of applicable services.

Patient Privacy

Healthcare providers using DigiMEDSPA remain responsible for managing their patient relationships, treatment activities, clinical decisions, and applicable patient authorizations.

DigiMEDSPA processes patient information on behalf of its healthcare customers according to applicable agreements, permitted purposes, and legal requirements.

Patients should contact their healthcare provider directly regarding questions about their medical records, treatment information, or the provider’s privacy practices.

Security Is an Ongoing Program

Security and privacy are not one-time certifications or product features.

DigiMEDSPA continuously evaluates its technology, policies, infrastructure, vendors, AI services, and security controls as our platform evolves.

As new capabilities are introduced, including Native AI, DigiMEDSPA evaluates how patient information is transmitted, processed, stored, accessed, and protected before those capabilities are introduced into applicable PHI-containing production workflows.

Questions About Security or HIPAA?

Healthcare organizations evaluating DigiMEDSPA may contact our team for additional information regarding our platform security, privacy practices, Business Associate Agreement, and healthcare data protections.

Talk to DigiMEDSPA

DigiMEDSPA

Native AI + EMR + Practice Management for Modern Healthcare Practices

Security. Privacy. Connected Healthcare.

Part 2

Business Associate Agreement (BAA)

DigiMEDSPA supports healthcare organizations that are subject to the Health Insurance Portability and Accountability Act (HIPAA).

When DigiMEDSPA creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a healthcare organization and a Business Associate Agreement is required under HIPAA, DigiMEDSPA will enter into an appropriate BAA with the healthcare organization.

Who Can Request a BAA?

A DigiMEDSPA BAA is available to eligible healthcare organizations using DigiMEDSPA services that involve the processing of PHI, including applicable:

  • Medical practices
  • Medical spas
  • Wellness clinics
  • Healthcare providers
  • Covered Entities
  • Other HIPAA-regulated healthcare organizations

What Does the BAA Cover?

The BAA describes DigiMEDSPA’s responsibilities regarding PHI processed on behalf of the healthcare organization, including applicable requirements related to:

  • Permitted uses and disclosures of PHI
  • Protection of PHI and electronic PHI
  • Administrative, physical, and technical safeguards
  • Security incident and breach notification responsibilities
  • Applicable subcontractors and service providers
  • Patient rights and required access to information
  • Return or destruction of PHI where applicable
  • DigiMEDSPA’s obligations as a Business Associate under HIPAA

DigiMEDSPA Subprocessors

DigiMEDSPA uses technology providers and subprocessors to operate portions of our healthcare platform.

When an applicable service provider creates, receives, maintains, or transmits PHI on behalf of DigiMEDSPA, we evaluate the service provider’s security and privacy practices and require appropriate contractual protections, including a Business Associate Agreement where required.

Native AI and PHI

Certain DigiMEDSPA Native AI capabilities may process PHI as part of authorized healthcare workflows.

Before a third-party AI service is authorized to process PHI within DigiMEDSPA production workflows, DigiMEDSPA evaluates the applicable service, configuration, data-handling practices, security controls, and contractual protections.

Where required, an appropriate Business Associate Agreement must be in place before PHI is transmitted to that service.

Request a DigiMEDSPA BAA

Existing DigiMEDSPA customers may contact their DigiMEDSPA representative to request or obtain the applicable Business Associate Agreement.

Organizations evaluating DigiMEDSPA may request information regarding our BAA as part of the sales and security review process.

Request BAA Information

Complete the form and a DigiMEDSPA representative will follow up regarding our Business Associate Agreement.

Do not include patient information or Protected Health Information (PHI) in this form.