Regulatory Compliance Statement

HIPAA Compliance & Patient Data Protection

How Eaze Billing protects Protected Health Information (PHI) under federal HIPAA rules, the HITECH Act, and the Florida Information Protection Act (FIPA, Florida Statutes § 501.171). Mandatory Business Associate Agreements executed prior to all engagements.

Effective & Review Date: May 2026 | Governing Jurisdiction: United States & State of Florida
Statutory Definitions

Defined Legal & Regulatory Terms

The following legal definitions govern all interactions between Eaze Billing and healthcare providers.

Term Formal Regulatory Definition
HIPAA Health Insurance Portability and Accountability Act of 1996 (Federal standards for health data privacy and electronic transaction security).
HITECH Act Health Information Technology for Economic and Clinical Health Act of 2009 (Strengthened enforcement penalties and mandatory breach notifications).
PHI Protected Health Information: Individually identifiable health data relating to physical/mental health conditions, provision of care, or financial payment.
ePHI Electronic Protected Health Information: PHI transmitted by, or maintained in, electronic media.
Covered Entity Healthcare providers, clinics, health plans, and clearinghouses transmitting health information electronically (Eaze Billing's clients).
Business Associate An entity providing operational services to Covered Entities involving access to PHI (Eaze Billing's legal operating status).
BAA Business Associate Agreement: A mandatory contract legally binding Business Associates to strict federal PHI security safeguards.
FIPA Florida Information Protection Act (Florida Statutes § 501.171): Florida state law governing personal data security and mandatory 30-day breach notifications.
Safeguards Framework

Three-Tier Security Safeguards Framework

We implement exhaustive administrative, physical, and technical safeguards complying with 45 CFR Parts 160 and 164.

1. Administrative Safeguards (45 CFR § 164.308)

  • • Routine vulnerability assessments & management audits
  • • Mandatory HIPAA training before staff receive system access
  • • Role-based access control (Principle of Least Privilege)
  • • Immediate credential revocation upon employee offboarding
  • • Formal workforce sanctions for procedural non-compliance
  • • Regularly tested data recovery and disaster response protocols

2. Physical Safeguards (45 CFR § 164.310)

  • • Restricted workstation access & facility security
  • • Mandatory automated screen lock upon inactivity
  • • Strict prohibition of personal USB/storage devices
  • • Clean-desk policy and zero physical paper charting
  • • Hardware sanitization and cryptographic media destruction
  • • Documented hardware inventory & relocation tracking

3. Technical Safeguards (45 CFR § 164.312)

  • • Unique user ID credentials & mandatory 2FA/MFA
  • • End-to-end TLS 1.2+ encryption in transit
  • • Industry-standard AES-256 encryption at rest
  • • Centralized immutable audit logs of all ePHI interactions
  • • Automatic session timeout logoffs
  • • Zero unencrypted public email transmission of ePHI
Contractual Protection

Mandatory Business Associate Agreement (BAA) Terms

Eaze Billing executes a comprehensive BAA with every client prior to initiating any billing, staffing, marketing, or technology service. Our standard agreement binds our firm to:

Use or disclose PHI only as permitted by the service contract or required by law.
Implement appropriate safeguards to prevent unauthorized PHI exposure.
Report any security incident or unauthorized disclosure without delay.
Bind all subcontractors and agents to the exact same rigorous restrictions.
Support patient rights to inspect, amend, and receive accounting of disclosures.
Return or certify destruction of all PHI upon service agreement termination.
Florida Law Adherence

Florida Information Protection Act (FIPA) Protocols

In addition to federal HIPAA mandates, Eaze Billing adheres strictly to Florida Statutes § 501.171 and the Florida Electronic Health Records Exchange Act.

Florida 30-Day Breach Notification Rule

Under FIPA § 501.171, affected Florida residents must be notified of confirmed data breaches as expeditiously as practicable and within a maximum of 30 days. For incidents impacting over 500 Florida residents, formal notice must be provided to the Florida Department of Legal Affairs.

HIPAA Federal Breach Notification

Compliant with 45 CFR Part 164 Subpart D, we notify Covered Entity clients without unreasonable delay and in no case later than 60 calendar days from discovery. Comprehensive breach logs and federal documentation are maintained for HHS Office for Civil Rights inspection.

Privacy Policy

Website Privacy Policy

Last Updated: May 2026 | Governing Jurisdiction: Florida, United States

1. Information We Collect

We collect information submitted directly through consultation forms (full name, email, phone number, clinic name, city, and operational notes). When visiting our website, technical telemetry such as IP address, browser type, device type, and visit timestamps may be collected to ensure security and performance.

Public Site Notice: The public website workwitheaze.com is an informational and lead-inquiry platform. It does not collect, process, or store Protected Health Information (PHI). Clinical providers must never submit patient medical records through public contact forms.

2. How We Use Information

Information is used solely to respond to consultation inquiries, prepare service proposals, provide contracted practice management services, and satisfy statutory compliance. We have never sold, rented, or leased personal information to third parties, and we never will.

3. Data Retention Schedule

Contact inquiries are retained for up to 3 years from last interaction. Client business records are retained for the duration of service plus 7 years in accordance with Florida healthcare and tax regulations.

Terms & Conditions

Terms of Service

Effective Date: May 2026 | Governing Law: State of Florida

1. Agreement to Terms

By accessing workwitheaze.com or engaging Eaze Billing for services, you agree to these Terms. Specific service deliverables, pricing, and operational timelines are formalized through separate Statements of Work (SOWs) and executed BAAs.

2. Invoicing & Payment Terms

Ongoing practice services are invoiced monthly and due within 15 calendar days of invoice date. Balances past 30 days are subject to late fees of 1.5% per month or the maximum permitted under Florida law.

3. Governing Law & Arbitration

These terms are governed by the laws of the State of Florida. Any unresolved disputes arising from services are subject to good-faith negotiation followed by binding arbitration administered under American Arbitration Association (AAA) rules in Florida.

Cookie Policy

Cookie & Tracking Technology Policy

Effective Date: May 2026

We use essential cookies strictly necessary for site navigation and form CSRF security, alongside anonymous performance analytics (Google Analytics) to measure site speed and user navigation patterns.

Strict PHI Exclusion: Cookies deployed on workwitheaze.com never capture, process, or link to patient medical records or Protected Health Information (PHI).

Compliance Officer Contact

For questions concerning HIPAA, privacy policies, or to exercise your rights under Florida FIPA, contact our compliance team directly at info@workwitheaze.com or +1 (307) 533-4609.