HIPAA readiness
HIPAA-covered businesses can start, with clinical safeguards still on.
PointMintz now allows medspa and healthcare-scope self-serve signup while keeping HIPAA category detection active for consent, audit, encrypted PHI surfaces, role controls, training, and retention workflows. Tenant owners remain responsible for their own covered-entity obligations and for executing any required BAA package before processing live PHI.
Where things stand today
- Signup status Unlocked
- Safeguard status Controls active
- Evidence status Private evidence
Controls wired today
- HIPAA-covered category detection in the compliance helper.
- Clinical consent templates and staff training gates.
- Encrypted clinical notes and appointment-photo paths for HIPAA-covered tenants.
- Clinical audit-log, disclosure-accounting, and BAA-tracking admin routes.
- Tenant Compliance Dashboard status rollup.
What still requires operational proof
- Executed BAAs with applicable infrastructure and communications vendors.
- Tenant-specific policies for PHI handling, staff access, and incident response.
- Encryption-at-rest evidence and PHI access-log verification retained outside Git.
- Counsel review before marketing any tenant as HIPAA compliant.