The HIPAA Privacy Act protects all individually identifiable health information. This Protected Health Information (PHI) can be found in paper records as well as electronic records. Because the HeRO software may contain PHI, MPSC has taken precautions to ensure its safety:

  • The HeRO software runs on hospital provided computers, typically a virtual server in the data center, under the protection of the hospital IT and physical security teams.
  • The HeRO software does not transmit any PHI outside of the hospital network. Thereby, MPSC does not maintain or store any PHI in the Company computer systems.
  • All of the calculations are performed on the server running HeRO in the hospital data center.
  • The HeRO software has been validated with many anti-malware, anti-virus solutions. We strongly recommend and support that the hospital deploy their preferred package onto the server which runs the HeRO software.
  • HeRO permits for the communication between the HeRO server and the HeRO viewing stations over SSL secure HTTPS protocols.

We follow the minimum necessary standard. Since there is no need for MPSC to store PHI, we don’t.

For more information about PHI, please go to the HHS website on the topic.