HIPAA Compliance Statement
Last updated: June 17, 2026
1. Our Commitment
We treat Protected Health Information (PHI) as confidential and apply administrative, physical, and technical safeguards modeled on the HIPAA Security Rule. Our goal is to protect the confidentiality, integrity, and availability of the health information entrusted to us.
2. Covered Entities and Business Associates
When a HIPAA-covered entity — such as a clinic, hospital, or laboratory — uses Looms to create or store PHI, Looms acts as a Business Associate. In those cases we will enter into a Business Associate Agreement (BAA) that defines each party's responsibilities for safeguarding PHI. Contact us to request a BAA.
3. Administrative Safeguards
- Role-based access so users can only reach the information their role permits.
- Workforce policies and least-privilege access to production systems.
- Regular review of access rights and security practices.
- Incident response procedures for suspected security events.
4. Technical Safeguards
- Encryption of data in transit using industry-standard protocols.
- Authentication and session controls to verify user identity.
- Audit logging of significant actions taken on records.
- Restricted, document-scoped verification that exposes only what is needed to confirm authenticity.
5. Physical Safeguards
PHI is stored with infrastructure providers that maintain physical security controls for their data centers, including restricted facility access and environmental protections.
6. The Minimum Necessary Principle
We design access and document verification around the minimum necessary standard. For example, when a document is verified via its QR code, the verifier sees only the limited details required to confirm authenticity — not the patient's broader medical history.
7. Patient Rights
Patients can access their own records, request corrections, export a copy of their data, and request deletion of their account. These controls support the access and amendment rights described in the HIPAA Privacy Rule.
8. Breach Notification
If we discover a breach of unsecured PHI, we will notify affected parties and any relevant covered entities without unreasonable delay and in accordance with applicable breach notification requirements.
9. Scope and Limitations
HIPAA applies to covered entities and their business associates. Individuals who use Looms purely for their own personal records are generally not subject to HIPAA, but we extend the same safeguards to all accounts. This statement is provided for transparency and is not legal advice.
10. Contact
To request a Business Associate Agreement or ask about our HIPAA practices, contact us through our Contact page or at privacy@looms.app.