Our Commitment to HIPAA Compliance
iDENTIFY.Agency (“iDENTIFY,” “we,” “us,” or “our”) provides marketing, advertising, website, and related services to dental and medical practices across the United States. In the course of providing these services, we may, in limited circumstances, come into contact with Protected Health Information (“PHI”) as defined under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (“HIPAA”). We are committed to safeguarding any such information in accordance with HIPAA’s Privacy, Security, and Breach Notification Rules.
Our Role Under HIPAA
Dental and medical practices we work with are generally “Covered Entities” under HIPAA. Where our services involve access to, or the potential exposure to, PHI on a client’s behalf – for example, certain reporting integrations, patient communication tools, or CRM workflows – iDENTIFY may act as a “Business Associate” of that practice, as defined under HIPAA. In such cases, we enter into a Business Associate Agreement (“BAA”) with the client prior to the applicable services beginning.
What We Do to Protect PHI
Where our engagement with a client involves systems or workflows that could touch PHI, we apply the following safeguards:
- Business Associate Agreements executed with clients before any PHI-adjacent service begins.
- Access to any client system or data limited to team members who require it to perform the contracted service, on a need-to-know basis.
- Encryption of data in transit and at rest for any systems we operate that may process PHI.
- Marketing and advertising campaigns designed to avoid the collection, transmission, or use of PHI in ad platforms (including Google Ads and Meta Ads), consistent with each platform’s own healthcare advertising policies.
- Website forms, chat tools, and lead-capture systems configured to avoid unnecessary collection of PHI, and to transmit any necessary data through secure, encrypted channels.
- Review generation and reputation management processes designed to avoid referencing or soliciting PHI in review requests or responses.
- SMS and email communication systems (including automated follow-up tools) configured with client consent workflows and secure data handling practices.
- Regular internal review of vendor and subprocessor tools used in client-facing systems for HIPAA-relevant security practices.
- Team training on HIPAA fundamentals and PHI handling practices for any team member working on accounts where PHI exposure is possible.
Third-Party Vendors and Subprocessors
Where we use third-party platforms or vendors (such as hosting providers, CRM platforms, or automation tools) in the course of delivering services that may involve PHI, we take reasonable steps to confirm those vendors are able to support HIPAA-compliant use, and we execute Business Associate Agreements with such vendors where required.
Breach Notification
In the event we become aware of a breach involving PHI in our custody or control, we will notify the affected client(s) without unreasonable delay, consistent with the requirements of the HIPAA Breach Notification Rule and the terms of the applicable Business Associate Agreement.
Client Responsibilities
HIPAA compliance is a shared responsibility. Clients remain responsible for their own HIPAA compliance program, including but not limited to their internal policies, workforce training, patient authorizations, and their own Notice of Privacy Practices. iDENTIFY’s role is limited to the specific services described in each client’s service agreement and any applicable Business Associate Agreement.
Marketing Platforms and PHI
iDENTIFY does not knowingly use PHI for advertising targeting, retargeting, or ad platform conversion tracking. Where analytics or conversion tracking is implemented on a client’s website or campaigns, it is configured to track marketing-relevant events (such as form submissions or calls) without transmitting PHI to third-party ad platforms.
No Legal Advice
This page describes iDENTIFY’s general practices and commitments regarding HIPAA compliance in connection with our marketing services. It is provided for informational purposes only and does not constitute legal advice. Dental and medical practices should consult their own legal counsel regarding their specific HIPAA obligations.
Updates to This Page
We may update this page from time to time to reflect changes in our practices or applicable law. The “27/08/26” date above reflects the most recent revision.
Contact Us
Questions about this HIPAA Compliance page or our data handling practices can be directed to:
Email:
hello@identify.agency
Phone:
(201) 401-2348
Mail: 2935 Tory Hill Lane Sugar Land, TX 77478