1. Overview & applicability
The Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations (the Privacy, Security, and Breach Notification Rules) govern how covered entities and their business associates handle PHI.
Important: MomPlan is not a HIPAA covered entity. HIPAA applies to our platform when we act as a Business Associate of a covered entity or its business associate — typically when a partner organization (health plan, clinic, county agency, or similar) uses MomPlan to assist clients with health-related benefits under a signed Business Associate Agreement (BAA).
Direct consumer use of the public MomPlan site without a partner BAA chain may not constitute a HIPAA-covered relationship. We still apply strong security controls to all sensitive data. Marketing references to "healthcare-industry safeguards" describe our security posture — not a representation that every interaction is HIPAA-regulated.
2. PHI we may process
PHI on MomPlan may include:
- Medicaid or CHIP enrollment and application status
- Health program eligibility indicators you provide
- Documents related to medical expenses or disability determinations
- Communications with caseworkers about health benefit appeals
We collect only the minimum PHI necessary to provide eligibility and application assistance services.
3. Safeguards
Our HIPAA-aligned controls include:
- Administrative — workforce training, access policies, incident response, and periodic risk assessments
- Physical — secure cloud data centers with SOC 2-certified providers; no PHI on unsecured local devices in production
- Technical — AES-256 encryption at rest, TLS 1.2+ in transit, role-based access control, audit logs, automatic session timeout, and multi-factor authentication for partner admin accounts
4. Minimum necessary & use limitations
MomPlan uses and discloses PHI only as permitted by our BAAs and applicable law — to perform eligibility services, facilitate applications you authorize, and meet legal obligations. We do not use PHI for marketing or unrelated commercial purposes.
5. Breach notification
We maintain procedures to detect, report, and respond to security incidents involving PHI. If a breach of unsecured PHI occurs, we will notify affected covered entities without unreasonable delay and in accordance with the HIPAA Breach Notification Rule and applicable state laws.
6. Individual rights
Requests to access, amend, or receive an accounting of PHI disclosures should be directed to the covered entity (e.g., your health plan or the partner organization assisting you). MomPlan will assist our covered-entity customers in fulfilling such requests as required by our BAAs.
7. Business Associate Agreements
Partner organizations requiring a BAA should contact compliance@momgovassistance.online. Our standard BAA incorporates HHS model provisions and addresses permitted uses, subprocessors, and termination obligations.