Why Trust us?

HIPAA Compliance at Trivent Legal

Software and hardware systems in place to maintain network and data security

Trivent legal - Technical Safeguards
  • The medical records are uploaded into a client portal which is protected by end to end encryption using HTTPS and SSL certificates.
  • The medical records are encrypted and stored in a high secure data center serviced by one of top cloud services provider.
  • Strong passwords are enforced, encrypted and stored in database.
  • Only authorized persons will be able to access the medical records only when they are working on that case.
  • Role based access controls in client portal are in place to prevent unauthorized access to the portal
  • Access restrictions like Firewall, whitelisting of IP and access to only company emails are in place to prevent access of Medical Records outside the organization.

On-site measures taken by Trivent to protect the PHI

Trivent legal - Physical Safeguards
  • Access restrictions like biometric access and monitoring like security guards, CCTV cameras are in place to prevent unauthorized access to Trivent premises.
  • Access restrictions like cameras or cell phones not allowed in the work zone and disabling of USB storage to prevent unauthorized transmission of data outside the company premises.

Internal policies and training implemented to secure the PHI

Trivent legal - Admin Safeguards
  • Non-Disclosure Agreement (NDA) is signed by all employees and contractors working for Trivent.
  • Intensive background check is conducted during the employee hiring process.
  • Security awareness and ethical training provided to all employees and contractors working for Trivent on a periodic basis.
  • Information Security Management System (ISMS) policies and procedures are in place to provide a secure work environment.

The PHI (Protected Health Information) is not available or disclosed to unauthorized persons.

Trivent legal - Confidentiality
  • The medical records are uploaded into client portal which is protected by end to end encryption using HTTPS and SSL Certificates.
  • The medical records are encrypted and stored in a high secure data center serviced by one of top cloud services provider.
  • Only authorized persons will be able to access the medical records only when they are working on that case.
  • Role based access controls in client portal are in place to prevent unauthorized access to the portal.
  • Access restrictions like firewall, whitelisting of IP and access to only company emails are in place to prevent access of medical records outside the organization.
  • Access restrictions like biometric access and monitoring like security guards, CCTV cameras are in place to prevent unauthorized access to Trivent premises.
  • Access restrictions like cameras or cell phones not allowed in the work zone and disabling of USB storage to prevent unauthorized transmission of data outside the company premises.
  • Non-Disclosure Agreement (NDA) is signed by all employees and contractors working for Trivent.
  • Security awareness and ethical training provided to all employees and contractors working for Trivent on a periodic basis.

The PHI is not modified or destroyed in an unauthorized manner

Trivent legal - Integrity
  • The medical records are accessed only in offline mode as PDF documents
  • No direct access to the PHI data storage through system or any other way is available
  • The PHI data is extracted and stored only in our end products like medical chronology
  • The PHI data is not extracted and stored in any easily identifiable manner like database or named entities

The PHI is easily accessible and usable by an authorized person

Trivent legal - Availability
  • Medical records are accessible only through the Client Portal software for authorized persons
  • The client portal and medical records are hosted in a high secure data center. The data center is services by one of the Top Cloud service providers with 24×7 availability.
  • Role based access controls are in place to allow access to authorized persons
Technical Safeguards

Software and Hardware systems in place to maintain network and data security

  • The Medical Records are uploaded into client portal which is protected by End to End encryption using HTTPS and SSL Certificates
  • The Medical Records are Encrypted and stored in a high secure data center serviced by one of Top Cloud services provider
  • Strong Passwords are enforced, encrypted and stored in database
  • Only authorized persons will be able to access the Medical Records only when they are working on that case.
  • Role based access controls in Client Portal are in place to prevent unauthorized access to the portal
  • Access restrictions like Firewall, whitelisting of IP and access to only company emails are in place to prevent access of Medical Records outside the organization
Physical Safeguards

On-site measures taken by Trivent to protect the PHI

  • Access restrictions like biometric access and monitoring like Security Guards, CCTV cameras are in place to prevent unauthorized access to Trivent premises.
  • Access restrictions like Cameras or Cell phones not allowed in the work zone and disabling of USB storage to prevent unauthorized transmission of data outside the company premises.
Administrative Safeguards

Internal policies and training implemented to secure the PHI

  • Non-Disclosure Agreement (NDA) is signed by all Employees and Contractors working for Trivent.
  • Intensive background check is conducted during the employee hiring process
  • Security awareness and Ethical training provided to all Employees and Contractors working for Trivent on a periodic basis.
  • Information Security Management System (ISMS) Policies and Procedures are in place to provide a secure work environment.
Confidentiality

Software and Hardware systems in place to maintain network and data security

  • The Medical Records are uploaded into client portal which is protected by End to End encryption using HTTPS and SSL Certificates
  • The Medical Records are Encrypted and stored in a high secure data center serviced by one of Top Cloud services provider
  • Strong Passwords are enforced, encrypted and stored in database
  • Only authorized persons will be able to access the Medical Records only when they are working on that case.
  • Role based access controls in Client Portal are in place to prevent unauthorized access to the portal
  • Access restrictions like Firewall, whitelisting of IP and access to only company emails are in place to prevent access of Medical Records outside the organization
Integrity

The PHI is not modified or destroyed in an unauthorized manner

  • The Medical Records are accessed only in offline mode as PDF documents
  • No direct access to the PHI data storage through system or any other way is available
  • The PHI data is extracted and stored only in our end products like medical chronology
  • The PHI data is not extracted and stored in any easily identifiable manner like database or named entities
Availability

The PHI is easily accessible and usable by an authorized person

  • Medical Records are accessible only through the Client Portal software for authorized persons
  • The Client Portal and Medical Records are hosted in a high secure data center. The data center is services by one of the Top Cloud service providers with 24×7 availability.
  • Role based access controls are in place to allow access to authorized persons

FAQs

Which AI models are used by Trivent?

Trivent uses a few AI models like Open AI and Google Gemini.  We use the AI Models provided by Companies in US.

Will the medical records uploaded to the Trivent Portal be used for Training the AI Model?

No. We will not be using the medical records for training purposes.

What are the safety measures taken by Trivent to safeguard the medical records?

We are HIPAA compliant, for more details, please refer to https://triventlegal.com/hipaa-at-trivent/

Where will the records be stored?

The records are stored in a secure AWS data centre in US.

How long the records are retained in your servers?

The records are stored in our servers till the case is completed and archived. The files are deleted 4 weeks after the case is marked as archive

Protecting Your Privacy, Preserving Your Rights