HIPAA and Your Health Records
Last updated 28 July 2026
Where trellOS creates, receives, maintains, or transmits Protected Health Information (“PHI”) on behalf of a Covered Entity or another Business Associate, trellOS functions as a Business Associate or subcontractor Business Associate under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), as amended by the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), including the HIPAA Privacy Rule, HIPAA Security Rule, and HIPAA Breach Notification Rule at 45 C.F.R. Parts 160 and 164.
trellOS performs those services pursuant to an applicable Business Associate Agreement (“BAA”). We may use or disclose PHI only as permitted or required by the BAA, as required by law, or as otherwise permitted by HIPAA. This distinction determines who is responsible for responding to requests concerning your medical records.
If you are a patient
You should ordinarily submit requests concerning your health records directly to the clinic, pharmacy, or healthcare organization that provided your care.
Depending on the circumstances, your rights under HIPAA may include the right to:
- Inspect or obtain a copy of your health records.
- Request an amendment to your health records.
- Request an accounting of certain disclosures.
- Request restrictions on certain uses or disclosures.
- Request confidential communications.
- Receive information about the organization’s privacy practices.
- File a complaint concerning the handling of your health information.
The applicable healthcare organization’s Notice of Privacy Practices explains which rights apply, how to exercise them, and where to submit a request. trellOS does not issue a Notice of Privacy Practices to patients solely by virtue of serving as a Business Associate.
If you submit a patient request directly to trellOS, we may verify the healthcare organization associated with the request and refer or transmit the request to that organization. We will not independently access, amend, delete, disclose, or otherwise act upon your medical records unless authorized or instructed to do so by the responsible organization and permitted by applicable law.
How we may use PHI
trellOS may use or disclose PHI only as permitted by the applicable BAA and applicable law. Depending on the services requested by the healthcare organization, permitted activities may include:
- Hosting, maintaining, and operating the trellOS platform.
- Supporting clinical, prescribing, pharmacy, administrative, and operational workflows.
- Routing authorized prescriptions, orders, or related information to designated recipients.
- Providing technical support, troubleshooting, security, backup, and disaster-recovery services.
- Maintaining audit logs and records required for security, compliance, and accountability.
- Supporting legally permitted healthcare operations or data-aggregation activities when expressly authorized by the BAA.
- Performing activities necessary for the proper management and administration of trellOS where permitted by the BAA and applicable law.
- Complying with legal obligations.
A BAA may not authorize trellOS to use or disclose PHI in a manner that would violate HIPAA if performed by the Covered Entity, except for limited activities expressly permitted by the HIPAA Rules.
Uses we prohibit
Except where expressly permitted by the applicable healthcare organization, the BAA, and applicable law, trellOS does not use PHI to:
- Sell patient information.
- Conduct third-party advertising.
- Market unrelated products or services.
- Build advertising profiles.
- Train general-purpose artificial intelligence models.
- Develop products for unrelated customers.
- Conduct independent research or benchmarking unrelated to the services provided to the healthcare organization.
Nothing in this section prohibits activities that are expressly authorized by the responsible healthcare organization and permitted under HIPAA, such as approved healthcare operations, quality-improvement activities, or appropriately de-identified data use. See also how we use AI.
Minimum-necessary access
Where the HIPAA minimum-necessary standard applies, trellOS limits the use, disclosure of, and requests for PHI to the minimum amount reasonably necessary to accomplish the intended purpose.
trellOS uses administrative and technical safeguards designed to limit access based on a person’s role, responsibilities, organization, and authorized purpose. These safeguards may include:
- Role-based access controls.
- Organization-level data segregation.
- Least-privilege access.
- Authentication and identity controls.
- Encryption in transit and at rest.
- Audit logging and monitoring.
- Access reviews and termination procedures.
Technical safeguards support, but do not replace, the policies, training, oversight, and contractual controls required to protect PHI.
Security incidents and breach notification
If trellOS discovers a breach of unsecured PHI involving information maintained on behalf of a Covered Entity, trellOS will notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery, unless the applicable BAA requires a shorter period.
To the extent available, trellOS will provide information reasonably necessary for the Covered Entity to evaluate the incident and satisfy its notification obligations, including:
- The nature and scope of the incident.
- The individuals or records believed to be affected.
- The types of information involved.
- The steps taken to contain and investigate the incident.
- Corrective actions and mitigation measures.
- Additional information required by the applicable BAA or law.
The Covered Entity is ordinarily responsible for notifying affected individuals, the U.S. Department of Health and Human Services, the media, or other authorities where required. A Business Associate may assist with or perform notifications where authorized by the Covered Entity.
Subcontractors
trellOS may use subcontractors to help provide hosting, infrastructure, security, support, communications, or other services.
A subcontractor that creates, receives, maintains, or transmits PHI on behalf of trellOS must enter into a written agreement imposing the applicable HIPAA restrictions, safeguards, reporting duties, and other Business Associate obligations.
Services that are not authorized to receive PHI are configured, where reasonably practicable, to receive only nonclinical or limited information necessary to perform their function. For example, an electronic notification may direct a user to securely sign in rather than include clinical details in the message itself.
Additional information concerning service providers is on the trellOS subprocessor list.
Substance-use-disorder records
Certain records concerning substance-use-disorder diagnosis, treatment, or referral for treatment may be protected by 42 C.F.R. Part 2 in addition to HIPAA.
When trellOS provides services to a federally assisted substance-use-disorder program or otherwise receives records subject to 42 C.F.R. Part 2, trellOS and the applicable organization will implement additional contractual, privacy, security, consent, notice, and breach-response requirements as required by law.
The 2024 amendments to 42 C.F.R. Part 2 became mandatory on February 16, 2026, and aligned several Part 2 requirements more closely with HIPAA while preserving additional protections for substance-use-disorder records.
A clinic’s status as a Part 2 program, and the application of Part 2 to particular records, must be assessed based on the organization, services, funding, and records involved. trellOS may require additional diligence and contractual terms before onboarding an organization that handles Part 2 records.
If you represent a clinic, pharmacy, or healthcare organization
Before trellOS receives PHI on behalf of an organization, the parties must execute an applicable BAA or otherwise document the legally permitted relationship.
The BAA addresses matters such as:
- Permitted and required uses and disclosures of PHI.
- Administrative, physical, and technical safeguards.
- Security-incident and breach reporting.
- Subcontractor obligations.
- Access, amendment, and accounting support.
- Government access to records relating to compliance.
- Return, destruction, or continued protection of PHI following termination.
- Responsibilities assigned to each party.
For a copy of the applicable BAA, security materials, or assistance with a diligence questionnaire, contact compliance@trellos.org.
Complaints
If you believe your health-information privacy rights have been violated, you may submit a complaint to:
- The clinic, pharmacy, or healthcare organization responsible for your records.
- trellOS at compliance@trellos.org.
- The U.S. Department of Health and Human Services, Office for Civil Rights.
trellOS prohibits retaliation against any person for submitting a good-faith privacy complaint, participating in an investigation, or exercising a right available under applicable law.
Questions about anything on this page? compliance@trellos.org
