> ## Documentation Index
> Fetch the complete documentation index at: https://handbook.helendelovely.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security Rule and ePHI Safeguards

> How electronic client information is protected, and the safeguards you're responsible for.

Almost all of our client information is electronic: the practice management system, email, the care portal, telehealth. The Security Rule requires us to protect it with administrative, physical, and technical safeguards. Here's what that means day to day.

## Where ePHI lives

Client information lives in these systems and nowhere else:

* **PracticeOS (GoHighLevel):** the client record, scheduling, communication, notes
* **The care portal:** intake and client-facing documents
* **Google Workspace** (Gmail, Drive, Calendar) under a signed business associate agreement, for internal work only
* **Stedi:** eligibility and claims
* **Gusto:** employee (not client) data

If client information is somewhere else (a personal note app, a text thread, a downloaded spreadsheet, a photo on your phone), it's in the wrong place. Move it or delete it and tell the practice manager.

## Administrative safeguards

* Every workforce member signs a confidentiality agreement and completes security training before access.
* Access is granted by role and limited to what the role needs. Clinicians see their own caseload. See [Getting access](/operations/getting-access).
* Access is reviewed when roles change and revoked the day someone leaves.
* The practice conducts a periodic risk analysis and keeps security policies for at least six years, as the rule requires.

## Physical safeguards

* Lock your screen when you step away, even for a minute. Set auto-lock to five minutes or less.
* Position screens so clients and visitors can't read them.
* Paper with client information, which should be rare, goes in a locked drawer, never left on a desk, and is shredded when no longer needed.
* Office keys and access are controlled. See [Office and facility](/operations/office-and-facility).

## Technical safeguards

* Unique login for every person, on every system. See [Passwords and user accounts](/privacy-and-security/passwords-and-user-accounts).
* Two-factor authentication on every system that offers it, which is all of ours.
* Encryption at rest on every device that touches ePHI (FileVault on Mac, BitLocker on Windows, default encryption on modern phones).
* Automatic updates turned on.
* Remote wipe enrollment for any mobile device with practice apps. See [Devices, mobile, and texting](/privacy-and-security/devices-mobile-and-texting).

## Phishing and social engineering

Most breaches start with a message that looks legitimate. Before you click a link, open an attachment, or enter a password:

* Check the sender's actual address, not just the display name.
* Be suspicious of urgency, unexpected invoices, password reset requests you didn't initiate, and anyone asking for credentials.
* When in doubt, don't click. Forward it to Zack and ask.

Nobody at the practice will ever ask for your password. Not Zack, not Helen, not a vendor.

## Your responsibilities, in one list

1. Unique credentials, never shared.
2. Two-factor on everything.
3. Encrypted, updated, auto-locking devices.
4. Client information only in practice systems.
5. Report anything odd immediately.

> **Why.** The Security Rule sounds technical, but nearly all of it comes down to these five habits. Do them and you've done most of the work.
