HIPAA & GDPR Compliance Statement
Last Updated: 6/1/2026
1. Introduction
At MySourceAssist, we are committed to maintaining the highest standards of data privacy and security. We recognize the critical importance of protecting personal and sensitive health information. This page outlines our commitment to compliance with the Health Insurance Portability and Accountability Act (HIPAA) in the United States and the General Data Protection Regulation (GDPR) in the European Union and European Economic Area.
2. HIPAA Compliance (For US Users)
MySourceAssist complies with the HIPAA Privacy, Security, and Breach Notification Rules to protect Electronic Protected Health Information (ePHI).
How We Protect ePHI
-
Administrative Safeguards: We conduct regular risk assessments, provide ongoing staff training on data security, and enforce strict access controls. Only authorized personnel with a legitimate "need to know" can access ePHI.
-
Physical Safeguards: Our physical servers and data environments are secured using industry-standard access controls, monitoring, and environmental protections.
-
Technical Safeguards: We employ end-to-end encryption for data at rest and in transit, multi-factor authentication (MFA), audit logs, and secure data backup/recovery protocols.
-
Business Associate Agreements (BAAs)
If MySourceAssist acts as a Business Associate, we require signed Business Associate Agreements (BAAs) with all covered entities and our subcontractors before handling any ePHI.
Patient Rights
Under HIPAA, individuals have the right to:
-
Request access to their health records.
-
Request corrections to their health information.
-
Receive an accounting of disclosures.
-
Request restrictions on how their data is used.
To exercise these rights, please contact our HIPAA Privacy Officer at Hippa@MySourceAsssit.Com.
3. GDPR Compliance (For EU/EEA Users)
For our users residing in the European Union or European Economic Area, MySourceAssist operates in full compliance with the GDPR. We act as a [Data Controller / Data Processor] regarding your personal data.
Lawful Basis for Processing
We only collect and process personal data when we have a lawful basis to do so. This includes:
-
Consent: When you have explicitly given us permission.
-
Contractual Necessity: When processing is necessary to provide our services to you.
-
Legitimate Interests: For our essential business operations, provided they do not override your privacy rights.
-
Legal Obligation: When we are required to comply with the law.
Data Subject RightsHIPPA / GDPR
HIPPA / GDPR
Under the GDPR, you have the right to:info@MySourceAssist.com
-
Right to Access: Request a copy of the personal data we hold about you.
-
Right to Rectification: Request corrections to inaccurate or incomplete data.HIPPA / GDPR
-
Right to Erasure ("Right to be Forgotten"): Request the deletion of your personal data.
-
Right to Restrict Processing: Limit how we use your data.
-
Right to Data Portability: Receive your data in a structured, commonly used format.
-
Right to Object: Object to the processing of your data for certain purposes (e.g., direct marketing).
International Data Transfers
If personal data is transferred outside the EU/EEA, MySourceAssist ensures that appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, to guarantee the security of your information.
4. Data Breach Notification
In the unlikely event of a data breach compromising ePHI or personal data, MySourceAssist has an incident response plan in place.
-
HIPAA: We will notify affected individuals, the Secretary of the Department of Health and Human Services (HHS), and, if required, the media, within the legally mandated timeframes (no later than 60 days following discovery).
-
GDPR: We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, and we will notify affected data subjects without undue delay if the breach poses a high risk to their rights and freedoms.
5. Contact Information
If you have any questions, concerns, or wish to exercise your rights under HIPAA or GDPR, please contact our Data Protection/Privacy Officer:
-
Email: info@MySourceAssist.com