HIPAA Compliance Policy
Effective Date: June 26, 2026 · Last Updated: June 26, 2026
ContractorBridge operates as a Business Associate (BA) under HIPAA where applicable. Agents using our platform to handle Protected Health Information (PHI) must maintain their own HIPAA compliance obligations as Covered Entities.
1. Overview
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for the protection of individually identifiable health information. ContractorBridge is committed to maintaining the privacy, security, and integrity of any Protected Health Information (PHI) that may be processed through our platform in connection with insurance contracting and benefits administration activities.
2. What Constitutes PHI
Protected Health Information includes any individually identifiable health information transmitted or maintained in any form or medium, including but not limited to:
- Names, addresses, dates of birth, Social Security numbers
- Medical record numbers, health plan beneficiary numbers
- Diagnosis codes, treatment information, prescription data
- Any information that could reasonably identify an individual in connection with health care
3. Our Safeguards
Administrative Safeguards: ContractorBridge maintains written HIPAA policies and procedures, designates a Privacy Officer, conducts workforce training, and performs regular risk assessments.
Physical Safeguards: Access to systems containing PHI is restricted to authorized personnel. Workstations and servers are secured against unauthorized physical access.
Technical Safeguards: We implement encryption in transit (TLS 1.2+) and at rest (AES-256), access controls, audit logging, and automatic session timeouts for all systems that may process PHI.
4. Business Associate Agreements (BAAs)
Where ContractorBridge acts as a Business Associate to a Covered Entity, we will execute a Business Associate Agreement (BAA) as required by HIPAA. Agents and agencies that are Covered Entities and wish to use ContractorBridge services in connection with PHI must contact us to establish a BAA prior to transmitting any PHI through our platform.
To request a BAA, contact: [email protected]
5. Breach Notification
In the event of a breach of unsecured PHI, ContractorBridge will notify affected Covered Entities without unreasonable delay and no later than 60 calendar days after discovery of the breach, as required by the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414).
6. Agent Responsibilities
Agents contracted through ContractorBridge who handle PHI in connection with insurance sales, enrollment, or benefits administration are independently responsible for their own HIPAA compliance obligations. ContractorBridge does not assume liability for an agent's independent HIPAA violations.
7. Contact
For HIPAA-related inquiries, BAA requests, or to report a potential privacy concern:
Privacy Officer
ContractorBridge Compliance Department
Email: [email protected]