HIPAA Compliance

Effective 10 October 2026 · Last updated 10 October 2026

1. Our position, stated plainly

NutriLink is built primarily for the Australian market and its privacy architecture is designed around the Privacy Act 1988 (Cth) and the Australian Privacy Principles. HIPAA (the Health Insurance Portability and Accountability Act) is a United States framework that applies to US "covered entities" (health plans, healthcare clearinghouses and certain US healthcare providers) and their "business associates".

NutriLink is not a US covered entity, and at this time NutriLink does not present itself as, and has not been assessed or certified as, a HIPAA Business Associate. We have not signed a standard Business Associate Agreement (BAA) as part of the default service, and we do not claim HIPAA compliance or certification.

If you are a US covered entity (or operate on US protected health information, "PHI"), you must not process PHI through NutriLink unless and until a BAA is executed with us and our subprocessors, and our assessment for your use case is complete. Contact support@nutrilink.pro to discuss.

2. Why this matters

Health data deserves the same care no matter which law applies, but accuracy matters too: claiming a certification we have not earned would be misleading. This statement exists so clinicians, clinics and patients know exactly where we stand.

3. Safeguards we apply to health information

Independently of HIPAA, NutriLink applies a defence-in-depth approach to protecting health information:

  • Encryption in transit: all traffic between your device and the platform is encrypted (TLS).
  • Encryption at rest: data stored by the platform provider is encrypted at rest.
  • Least-privilege access control: row-level permissions mean a user can only read and change records tied to their own account — a patient sees their own data and their assigned nutritionist; a nutritionist sees only their own patients; other users cannot reach them.
  • Authentication controls: password and Google sign-in, optional device PIN lock and biometric unlock, and session security managed by the platform.
  • Role separation: platform administrators have access only for support, security and billing administration, and the AI support assistant has no access to patient or account records at all.
  • Vendor management: the underlying hosting, payment (Stripe) and email providers are bound by their own security obligations and the platform’s data-processing terms.
  • Breach response: a documented assessment and notification process consistent with Australia’s Notifiable Data Breaches scheme.

4. How this maps to HIPAA-style safeguards

For transparency, here is how our practices relate to the safeguards HIPAA’s Security Rule expects. This is an informational mapping only — it is not a HIPAA assessment and not a compliance claim.

  • Access control (similar to 45 CFR §164.312(a)): implemented via account-based, row-level permissions.
  • Transmission security (§164.312(e)): TLS encryption in transit.
  • Audit and integrity: platform logging of application activity through the hosting provider; full clinical audit trails are not provided as a standard feature today.
  • Minimum necessary: enforced structurally by role-based access rather than by formal minimum-necessary policies.
  • Business Associate Agreements: not offered as part of the default service at this time.

5. What we would need before supporting US PHI

To support a US covered entity we would need, at minimum: an executed BAA with the covered entity; confirmation that the hosting, payment and email subprocessors can support the arrangement (including any BAA they offer); a documented risk analysis for the use case; and agreement on breach notification timelines consistent with the HIPAA Breach Notification Rule. Until then, US PHI should not be stored in NutriLink.

6. Questions

This statement is effective 10 October 2026 and is reviewed alongside our Privacy Policy (currently 10 October 2027). Questions about this page: support@nutrilink.pro, or a ticket with the category "Privacy" from the Support section.