CACTUS is committed to providing a secure, compliance-ready platform for clients operating within the healthcare ecosystem. Our infrastructure is designed to support compliance with Health Insurance Portability and Accountability Act of 1996 (HIPAA), where required, subject to the execution of a formal Business Associate Addendum (BAA) process.
Our HIPAA workflow:
- No PHI by Default: Use of the Services does not involve the collection, access, use, or processing of Protected Health Information (PHI) unless a duly executed Business Associate Addendum (BAA) is in place.
- Request a BAA: If your organization is a "Covered Entity" or "Business Associate" under HIPAA and requires disclosing or processing PHI, please request a BAA by emailing us at privacy@cactusglobal.com.
- Review & Sign: Upon receipt of request, we will review your data requirements and where appropriate, provide our standard BAA for electronic signature.
For consistency, operational integrity, and auditability across our platform, CACTUS uses a standardised BAA and is generally unable to accept client-drafted or customised agreements. If you are a covered entity, you agree not to use CACTUS services for any purpose or in any manner involving PHI without first entering into a BAA and ensuring that your use of the services complies with applicable HIPAA requirements.