The Health Insurance Portability and Accountability Act, HIPAA (including the Privacy Rule, Security Rule, Breach notification Rule, and Health Information Technology for Economic and Clinical Health Act), requires Covered Entities and Business Associates to take certain measures to protect health information that can identify an individual. It also provides certain rights to individuals. Zoho does not collect, use, store or maintain health information protected by HIPAA for its own purposes. However, Zoho Campaigns provides features to help its customers secure health related data within the premises of HIPAA compliance.
HIPAA requires Covered Entities to sign a Business Associate Agreement (BAA) with its Business Associates. You can request our BAA template by sending an email to
legal@zohocorp.com.
How to apply HIPAA compliance in Zoho Campaigns?
Admins in Zoho Campaigns can secure and restrict export of individuals' health information and stay compliant with the HIPAA guidelines by doing the following:
Marking fields that contain PHI: Marking fields containing personal health details will help the system identify and restrict access to these fields through API and prevent the export of these field values. For example, fields that contain surgical history, symptoms, medication details, etc
Note: Only Custom fields can be marked as fields with PHI ( Protected Health Information. Standard fields cannot be marked Setting restrictions for the data marked as PHI: There are two options for restricting personal data from being accessed outside Campaigns. Any of these options can be enabled depending on the org's requirements:
- Restrict data access through API: Other applications can connect with Zoho Campaigns using API and data can be transferred. You can ensure that personal health data of your customers is not shared in the process, by restricting transfer of personal health data to other applications via API.
- Restrict data export: While exporting data from the Zoho Campaigns account you may want to withhold personal health information from being exported by checking this option.
- Encrypting PHI fields: Fields that contain personal health information can be encrypted for additional security. Though field encryption is not a mandatory step in Zoho Campaigns, we strongly recommend you enable encryption as it is the best practice to prevent unauthorized access to confidential data.
Note: The custom fields are not encrypted by default. You are required to encrypt it manually. - From the Navigation toolbar select Settings. Under General, select Compliance settings and click HIPAA Compliance.
- Toggle the HIPAA compliance settings Switch on. Once you toggle this on, switches that enable restriction of personal health data appear.
- Toggle Restrict data export switch or Restrict data export through APIs switch on. This restricts users from sharing data.
How to mark a field as Containing personal data?
- From the Navigation toolbar select Settings. Under Customization, select Custom Fields.
- Click Create Custom Field in the Accounts page.
- Check Contains Personal health data check box, after filling out the custom field details. You can also edit an existing field and mark or unmark it as containing personal data
How to encrypt a field containing health data?
- From the Navigation toolbar select Settings. Under Customization, select Custom Fields.
- Click Create Custom Field in the Accounts page.
- Check the Encrypt field data box on, after filling out the custom field details. You can also edit an existing field and encrypt or decrypt its data.
How to disable HIPAA compliance?
- From the Navigation toolbar select Settings. Under General, select Compliance settings and click HIPAA Compliance.
- Toggle the HIPAA compliance settings Switch OFF. Once you toggle this off, a confirmation dialog box appears.
- Click Yes, Disable HIPAA Compliance.
- Once you disable HIPAA compliance, the restriction to export and other activities related to it gets revoked.
Retrieving the audit log
As a covered entity it is your responsibility and best practice to export logs periodically and preserve them for the required period. To facilitate this we allow you to export data as and when required using the
Export Audit Log option. In Zoho Campaigns audit log is available for 6 months by default. In case you require data beyond 6 months you can reach out to
support@zohocampaigns.com.