HIPAA-Compliant Privacy Practices
Layera collects the following categories of information to provide our healthcare compliance management services:
Role-based access controls, workforce training requirements, comprehensive audit logging of all PHI access, and incident response procedures.
AES-256-GCM encryption for sensitive data at rest, TLS encryption in transit, automatic session timeouts (15-minute idle), account lockout after failed login attempts, strong password requirements, and comprehensive security headers (CSP, HSTS, X-Frame-Options).
Secure hosting infrastructure with access controls, data backup procedures, and disaster recovery planning.
We retain your data as required by HIPAA (minimum 6 years for compliance records) and applicable state regulations. Audit logs are retained for a minimum of 6 years. You may request data export or deletion subject to legal retention requirements.
In the event of a breach of unsecured PHI, we will notify affected individuals within 60 days of discovery, as required by the HIPAA Breach Notification Rule (45 CFR Part 164, Subpart D). We will also notify the HHS Secretary and, if applicable, the media.
In addition to federal HIPAA requirements, we comply with state-specific healthcare privacy laws including the Texas Medical Records Privacy Act (TMRPA), Texas Health and Safety Code Chapter 181, and any other applicable state regulations based on your agency's operating state.
For privacy concerns, data requests, or to report a security incident, contact our HIPAA Privacy Officer at privacy@complianceai.com.
Last updated: February 2026
This Privacy Policy is reviewed and updated annually or as required by regulatory changes.