HIPAA Compliance
Table of contents
Our Commitment to HIPAA Compliance
This page describes our organizational compliance program. For your individual rights and how your information may be used, see the HIPAA Notice of Privacy Practices at /privacy/hipaa-notice.
Aperion Health is committed to full compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Health Information Technology for Economic and Clinical Health (HITECH) Act, and all applicable federal and state privacy and security regulations.
As a healthcare navigation and spend optimization company, we routinely handle Protected Health Information (PHI). Safeguarding that information is foundational to how we operate, build technology, and serve our members.
Our compliance program is built to:
Protect the confidentiality, integrity, and availability of PHI
Limit access to and use of PHI to the minimum necessary
Hold our workforce and vendors accountable to HIPAA standards
Detect, respond to, and report security incidents and breaches
Our HIPAA Compliance Program
Aperion Health maintains a comprehensive, documented compliance program aligned with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
The program is overseen by designated Privacy and Security Officers and is reviewed and updated regularly to reflect changes in regulation, technology, and our services.
Core pillars of the program:
Administrative, physical, and technical safeguards
Written policies, procedures, and workforce sanctions
Ongoing risk analysis and risk management
Business Associate Agreements with vendors handling PHI
Workforce privacy and security training
Incident response and breach notification readiness
Administrative Safeguards
Administrative safeguards are the policies, procedures, and oversight that govern how our workforce protects PHI.
Designated HIPAA Privacy Officer and Security Officer
Documented privacy and security policies reviewed on a regular cadence
Role-based access controls following the minimum necessary standard
Workforce screening, confidentiality agreements, and sanction policies
Regular workforce training and awareness programs
Periodic internal audits and compliance reviews
Physical Safeguards
Physical safeguards protect the systems, equipment, and facilities that store or process PHI from unauthorized physical access, tampering, and theft.
Controlled access to facilities and infrastructure handling PHI
Workstation use and security policies
Device and media controls for storage, reuse, and secure disposal
Use of reputable cloud infrastructure with HIPAA-eligible services and signed agreements
Technical Safeguards
Technical safeguards are the technology controls that protect PHI and govern access to it within our systems.
Encryption of PHI in transit and at rest
Unique user identification and strong authentication
Role-based authorization and least-privilege access
Audit logging and monitoring of access to PHI
Integrity controls to prevent improper alteration or destruction of data
Automatic logoff and session protection on sensitive workflows
Minimum Necessary Standard
We apply the HIPAA "minimum necessary" standard: workforce members and systems are granted access only to the PHI required to perform a specific function.
Reporting provided to employers and plan sponsors is aggregated or de-identified so that individual PHI is not disclosed without authorization or a permitted legal basis.
Business Associates & Vendors
We never sell PHI. Vendors handling PHI are contractually bound to HIPAA-equivalent safeguards.
When a vendor or partner creates, receives, maintains, or transmits PHI on our behalf, we require a Business Associate Agreement (BAA) before any PHI is shared.
Each Business Associate Agreement requires vendors to:
Use and disclose PHI only as permitted by the agreement and law
Implement appropriate administrative, physical, and technical safeguards
Report security incidents and breaches to Aperion Health
Return or securely destroy PHI when the relationship ends
Workforce Training & Accountability
Every workforce member with access to PHI completes privacy and security training and acknowledges our policies.
Violations of HIPAA policies are subject to a documented sanction process, up to and including termination and, where applicable, referral to authorities.
Risk Analysis & Ongoing Monitoring
We conduct periodic risk analyses to identify potential vulnerabilities to the confidentiality, integrity, and availability of PHI, and we implement risk management measures to address identified risks.
Security monitoring, assessments, and program reviews are performed on an ongoing basis as part of continuous improvement.
Incident Response & Breach Notification
Aperion Health maintains an incident response process to detect, contain, investigate, and remediate security incidents involving PHI.
In the event of a breach of unsecured PHI, we follow the HIPAA Breach Notification Rule, including notifying affected individuals, the U.S. Department of Health and Human Services (HHS), and, where required, the media within the timeframes set by law.
Your Rights as a Member
HIPAA gives you specific rights regarding your health information. These rights, and how to exercise them, are described in detail in our HIPAA Notice of Privacy Practices.
Your rights include:
Access and obtain copies of your information
Request amendment of inaccurate information
Request an accounting of certain disclosures
Request restrictions and confidential communications
Receive a paper copy of the Notice of Privacy Practices
Reporting a Concern or Complaint
No retaliation: You will not be penalized or retaliated against for raising a concern or filing a complaint.
If you believe your health information has been handled improperly, or you have a question about our compliance program, contact the Aperion Health Privacy Officer. You may also file a complaint with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR).
Contact Our Privacy Officer
Questions about our HIPAA compliance program can be directed to the Aperion Health Privacy Officer.
Aperion Health Privacy Officer
Minneapolis, Minnesota
Phone: (612) 208-7537
Email: info@aperion.health
Website: aperion.health
Member Portal: portal.aperion.health/login