Legal & compliance11 documents

HIPAA and Your Health Records

Last updated 28 July 2026

trellOS generally operates as a Business Associate, not as a healthcare provider, health plan, or other HIPAA Covered Entity. The clinic, pharmacy, or other healthcare organization using trellOS is ordinarily the Covered Entity or another Business Associate responsible for the underlying healthcare relationship.

Where trellOS creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Covered Entity or another Business Associate, trellOS functions as a Business Associate or subcontractor Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), including the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule at 45 C.F.R. Parts 160 and 164.

trellOS performs those services pursuant to an applicable Business Associate Agreement (“BAA”). We may use or disclose PHI only as permitted or required by the BAA, as required by law, or as otherwise permitted by HIPAA. This distinction determines who is responsible for responding to requests concerning your medical records.

Questions about anything on this page? compliance@trellos.org