top of page

HIPAA Privacy and Security Policy

certified-hipaa-compliant

Purpose

 

This HIPAA Privacy & Security Policy (“Policy”) establishes the standards and procedures used by LifeLine Medical Services (“Company,” “we,” “our,” or “us”) to protect Protected Health Information (“PHI”) collected, transmitted, stored, or accessed through our non-emergency medical transportation (“NEMT”) services and website.

Our organization is committed to complying with applicable federal and state privacy and security laws, including:

  • The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”)

  • The HIPAA Privacy Rule

  • The HIPAA Security Rule

  • The HIPAA Breach Notification Rule

  • Applicable Pennsylvania privacy and healthcare regulations

Website Data Handling

Our website may collect information through:

  • Appointment request forms

  • Contact forms

  • Eligibility verification requests

  • Secure patient portals

  • Referral submissions from healthcare organizations
     

Any PHI submitted through the website is protected using industry-standard safeguards including:

  • Secure HTTPS/TLS encryption

  • Access controls

  • Password protection

  • Secure hosting environments

  • Role-based permissions

  • Audit logging where applicable


Users are encouraged not to submit unnecessary medical details through public or unsecured forms.

HIPAA Security Safeguards

The Company maintains administrative, technical, and physical safeguards designed to protect PHI and ePHI.
 

Administrative Safeguards

We implement:

  • Workforce HIPAA training

  • Confidentiality agreements

  • Role-based access management

  • Security awareness programs

  • Risk assessments

  • Incident response procedures

  • Vendor oversight and compliance reviews
     

Technical Safeguards

We utilize:

  • Encryption in transit

  • Secure passwords and authentication

  • Firewalls and endpoint protection

  • Access monitoring and logging

  • Automatic session timeouts

  • Secure backups

  • Anti-malware protections
     

Physical Safeguards

We maintain:

  • Controlled facility access

  • Secure workstation practices

  • Device protection policies

  • Proper disposal of sensitive information

  • Mobile device security standards

Website Cookies and Analytics

Our website may use cookies, analytics tools, and performance monitoring technologies to improve functionality and user experience. We take reasonable steps to avoid transmitting PHI through analytics or advertising platforms inappropriately. Users may adjust browser settings to manage cookie preferences.

Third-Party Services

The website may utilize third-party services for:

  • Secure hosting

  • Appointment scheduling

  • Communication tools

  • Form processing

  • Analytics

Where applicable, vendors handling PHI are required to maintain HIPAA-compliant safeguards and execute Business Associate Agreements.

Contact Us

If there are any questions regarding this privacy policy, you may contact us using the information below:

contact@lifelinemedicalservices.com

(215) 674-3003

bottom of page