Skip to content
Back to Little Files

SECURITY & HIPAA COMPLIANCE

Patient privacy is part of running the clinic.

Little Files is HIPAA compliant, with a Business Associate Agreement available for US clinics. Permission controls, private document access, and recorded activity support the people responsible for sensitive patient and employee information.

BAA available for US clinics

Permissions by responsibility

Application routes check permissions. Clinical, HR, billing, employee, and guardian workflows have different access scopes so records can be made available to the people responsible for the work.

Private document access

Documents are retrieved through authenticated application routes with access checks. File storage paths are not used as public document links in the interface.

Recorded activity

The application records audit events for account activity and record changes. Staff responsible for security should establish how those records are reviewed and how concerns are escalated.

HIPAA and the BAA process

MEMBA LTD offers a Business Associate Agreement for US customers subject to HIPAA. Contact info@littlefiles.net to request the agreement and discuss the scope of the services that will handle protected health information.

The appropriate BAA must be executed before PHI is processed. Your onboarding review should cover service providers, applicable safeguards, risk management, incident handling, retention, and the clinic’s responsibilities.

HIPAA compliance is an ongoing responsibility. Clinics remain responsible for their own access decisions, procedures, and appropriate use of patient information. See HHS guidance for cloud services and business associates.

What to discuss before onboarding

  • Your data flows, clinic roles, and access requirements.
  • Hosting, storage, and other providers handling your information.
  • Required agreements and any international processing arrangements.
  • Retention, backups, data return, deletion, and incident contacts.
  • Security evidence needed for your own assessment.

Report a concern

Email info@membaltd.com with a short description and a way to contact you. Do not include patient records, passwords, or access tokens in the message. We can discuss an appropriate way to exchange further details.

For website information, read the privacy notice. Requests about a patient’s record should normally start with the clinic responsible for that record.

BRING YOUR WORKFLOW

See it with your team’s questions in mind.

Tell us which security and contractual questions your clinic needs answered. Request the BAA and relevant documentation before any patient data is shared.

Request a demo