→ Message content restrictions — blocks sending of PHI (diagnoses, procedures, test results) via SMS
→ BAA tracking — records Business Associate Agreements with all sub-processors
→ Minimum necessary principle — outbound messages limited to date/time only, no clinical details
→ Enhanced audit logging — all message access events recorded with user identity and timestamp
Requires a BAA with Piggyback.
Request BAA →