HIPAA Notice
Effective date: July 28, 2026 · VigilReady LLC
The Role of VigilReady Under HIPAA
VigilReady LLC is a Business Associate under HIPAA, not a covered entity. We provide a document management platform that disability services agencies (“covered entities” or “customer organizations”) use to manage compliance documentation for their own clients. This page explains our obligations as a Business Associate. It is not a Notice of Privacy Practices.
Looking for a Notice of Privacy Practices?
Under HIPAA, only a covered entity — the agency providing your care or services — issues a Notice of Privacy Practices. VigilReady does not provide services directly to individuals and does not issue one. If you are a client of a disability services agency that uses VigilReady, please contact that agency directly for their Notice of Privacy Practices and to exercise any rights regarding your Protected Health Information (PHI).
How We Handle PHI as a Business Associate
We maintain a Business Associate Agreement (BAA) with each customer organization governing our handling of PHI on their behalf, and a signed BAA with our cloud infrastructure provider (Amazon Web Services) covering all PHI stored or processed on their services. We use and disclose PHI only as permitted by our BAA with the applicable customer organization and as required by law, and we maintain an append-only audit trail of PHI access as required by HIPAA.
Breach Notification
If we discover a breach of unsecured PHI, we will notify the affected customer organization(s) in accordance with the timelines in our BAA and applicable law. The customer organization, as the covered entity, is responsible for any further notification to affected individuals unless otherwise agreed.
Contact
Customer organizations with questions about our Business Associate obligations can contact us at [email protected]. Individuals seeking to exercise HIPAA rights should contact their servicing agency directly.