Trust Center → HIPAA

HIPAA, honestly

Status Post is not a HIPAA covered entity and is not a business associate of one. Anyone who tells you a social network is "HIPAA compliant" is selling you something.

What that means

HIPAA binds health plans, healthcare clearinghouses, providers who bill electronically, and the vendors handling protected health information on their behalf. Status Post is none of those. We hold no medical records, we are not part of your employer's systems, and nothing you write here is a medical record.

What it means for you, which is the part that matters

HIPAA does not stop applying to you just because it does not apply to us. You are still bound by it at work, and by your employer's policies, and by your licensing board. A post here that identifies a patient is a problem for you regardless of what our platform is or is not.

The practical rule

Write about your experience, not the patient's. No names, no dates, no room numbers, no facility plus date plus diagnosis, no photographs taken in a clinical area, no detail so specific that one person could be picked out of it. Our composer opens in a template built to keep you on the right side of that line — see the community guidelines.

Why we say this out loud instead of claiming compliance

"HIPAA compliant" on a network like this one would be a false claim, and a false claim about the exact thing our members would be fired over. The truthful statement is less reassuring and more useful: we are not a covered entity, we designed the product so that we hold as little about you as possible, and the rules you work under are still yours.