Help Scout and HIPAA
Help Scout maintains ongoing compliance with the U.S. Health Insurance Portability and Accountability Act (HIPAA) and is able to process, maintain and store protected health information for any entities restricted by these regulations. HIPAA support is available on the Plus and Company plans only.
Signing a BAA with Help Scout
Help Scout will sign a business associate agreement (BAA) with your organization, which you can access from the links below. Our team will receive a notification of the signed BAA and we will turn on the HIPAA feature if you are on a Plus or Company plan.
- For subcontractors: https://www.helpscout.net/company/legal/baa-subcontractor
- For covered entities: https://www.helpscout.net/company/legal/baa-covered-entity
What's involved in HIPAA compliance?
We complete annual risk assessments and employee training as required by HIPAA. Additionally, we've gone to great lengths to ensure that data is properly secured and encrypted.
Where is Help Scout customer data hosted?
With the exception of off-site backup and redundancy infrastructure, Help Scout is hosted on Amazon Web Services (AWS), a highly scalable cloud computing platform with end-to-end security and privacy features built in.
What sort of application security is in place?
All Help Scout web application communications are encrypted over 256 bit SSL, which cannot be viewed by a third party and is the same level of encryption used by banks and financial institutions.
Can I edit or remove PHI from a thread if needed?
Yes. This is helpful if there are multiple parties involved in one conversation. Through a thread options menu, you can edit, delete, or hide thread contents. This prevents that information from being sent out again, or from being quoted in a future reply.
Who has access to our Help Scout account?
All Help Scout employees are able to access customer accounts for the sole purpose of lending a hand. We don't access customer accounts unless we're explicitly asked for help.
Are we able to export our data if we decide to leave one day?
All customer and conversation data can be accessed at any time via our Mailbox API. We're working on in-app export tools to make that process easier for folks without API knowledge.
Can you sign our BAA, or make changes the Help Scout BAA upon request?
Unfortunately, we're not able to have unique agreements with customers. We believe our BAAs accurately cover the scope of our relationship, and for legal reasons, cannot make adjustments to our BAAs.
Does Help Scout have a policy that identifies and determines controls regarding the proper use of workstations to support access and protection of ePHI?
All production data is in a VPC (virtual private cloud). Internal access is firewalled and users must be authenticated on the VPN and via multi-factor authentication to access anything.
Do you have a security policy to help ensure the confidentiality, integrity, and availability of ePHI? Do you have a SOC2/3 report?
Does Help Scout have a security control policy (locked doors, surveillance cameras, alarms) to prevent theft of ePHI?
Do you have procedures for terminating access to systems containing ePHI when a team member is no longer employed at Help Scout?
Have you taken steps to protect the organization from malicious software, including the application security patches?
Have passwords been implemented that are unique to a user and comply with best practice components including password length, complexity, and duration?
Do you routinely conduct audits of your application, such as code reviews, static or dynamic code analysis, penetration tests, or vulnerability scans?
Yes. Code reviews and analysis are conducted by all engineers as a part of the development process. Help Scout does application scans and penetration tests at least quarterly.