How we keep Drupal out of HIPAA scope
The cheapest way to stay compliant is to keep protected health information out of the content management system entirely. DoodleWeb architects healthcare Drupal sites so the CMS renders public content and hands off anything patient specific to a system already covered by a business associate agreement.
- No PHI in Drupal nodes, form submissions, logs or analytics.
- Scheduling and portal actions handed off to the covered system, not proxied.
- Provider and location data synced from the credentialing source of record.
- Analytics configured to strip identifiers from URLs and form paths.
