Skip to main content

What is HIPAA compliance, and how does it protect me?

Updated over 2 months ago

At Disclo, protecting employee privacy and security is core to our product and processes. Our platform is built with strong, layered controls and has been independently audited: we completed a SOC 2 Type 2 examination by Sensiba San Filippo LLP, and our controls are continuously monitored by Vanta.

What we collect (and why)
We only collect information needed to manage workplace accommodation requests and follow applicable privacy laws and regulations, including HIPAA and the GDPR.

How we protect data

  • Encryption in transit and at rest

  • Secure storage with strict access controls and least-privilege permissions

  • Auditing and monitoring of systems and access

  • Employee training on privacy, security, and confidentiality

Access to sensitive information
Access to sensitive data is limited to authorized Disclo personnel with a business need.

Important note on PHI
While Protected Health Information (PHI) is confidential by default, there are limited situations where an employer may need to view underlying health information or documentation. In those extenuating circumstances, the employer will manually request the information, and any disclosure will occur only when appropriate and in accordance with privacy laws and ADA confidentiality rules.

Our commitment is ongoing: independent auditing (SOC 2 Type 2) and continuous monitoring (Vanta) give additional assurance that our security practices align with industry standards.

Did this answer your question?