Dastify Solutions

Security & Compliance

Enterprise-Grade Security

Dastify uses client-approved access and defined workflows for the services it provides. Business Associate Agreements are available for engagements involving protected health information. Contact our compliance team for documentation relevant to your security review and proposed service scope.

HIPAA Compliant
Workflows

BBB
Accredited

HIPAA Compliance

Dastify uses client-approved access and defined workflows for the services it provides. Business Associate Agreements are available for engagements involving protected health information. Contact our compliance team for documentation relevant to your security review and proposed service scope.

Ask our compliance team for workforce training records and the policies applicable to your engagement.

Administrative Safeguards
Security management processes, workforce training, access management, and contingency planning.

Physical Safeguards
Facility access controls, workstation security, and device/media controls for all PHI storage.

Technical Safeguards
Access controls, audit logs, integrity verification, and transmission security for all systems.

Documentation
Policies, procedures, risk assessments, and training records maintained for 6+ years.

Security Measures

Our security infrastructure is designed to protect against unauthorized access, data breaches, and cyber threats. We employ multiple layers of security controls and continuously monitor our systems for potential vulnerabilities.

Encryption
Ask our compliance team for the encryption requirements and configurations applicable to your engagement, including data at rest and data in transit.

Multi-Factor Authentication (MFA)
Access requirements are defined for each engagement. Ask our compliance team about authentication controls for the systems and accounts involved.

Role-Based Access Control (RBAC)
Access to patient data is restricted based on job function and need-to-know basis. We follow the principle of least privilege for all system access.

Security Monitoring & Response
Ask our compliance team for the monitoring, incident-response, backup, retention and recovery arrangements applicable to the systems used for your engagement.

Regular Penetration Testing
Security assessments and testing are performed based on applicable risk, system scope, and security requirements.

Regulatory Compliance

Beyond HIPAA, Dastify Solutions maintains compliance with a comprehensive set of healthcare and data protection regulations applicable to medical billing services.

42 CFR Part 2
Enhanced privacy protections for substance use disorder (SUD) patient records in behavioral health billing.

Mental Health Parity Act
For services within our role and contractual scope, applicable privacy and security requirements are addressed through documented processes and client-approved workflows.

CMS Guidelines
Access controls, audit logs, integrity verification, and transmission security for all systems.

State Privacy Laws
Applicable state privacy requirements are addressed based on the client, service, jurisdiction, and contractual scope.

Certifications

HIPAA compliance
Reviewed Annually
Active

BBB
Accredited Business
Active

Security Stats

Uptime SLA
Service Availability

Security Incidents
Managed

Security Questions?

Our compliance team is available to answer questions about our security practices and provide documentation for your due diligence requirements.

Contact Compliance Team

Your Data is Protected

We implement multiple layers of protection to ensure your practice’s data remains secure at every stage—from transmission to storage to access.

Encrypted at Rest
Encryption controls are applied to systems and data within the scope of our security policies and applicable service configurations.

Encrypted in Transit
Ask our compliance team for the encryption requirements and configurations applicable to your engagement, including data at rest and data in transit.

Access Controlled
Access requirements are defined for each engagement. Ask our compliance team about authentication controls for the systems and accounts involved.

Securely Backed Up
Ask our compliance team for the monitoring, incident-response, backup, retention and recovery arrangements applicable to the systems used for your engagement.

Frequently Asked Questions

Do you sign a Business Associate Agreement (BAA)?
Yes, we execute a comprehensive Business Associate Agreement with every client before handling any Protected Health Information. Our BAA covers all HIPAA requirements and clearly defines the responsibilities of both parties regarding PHI protection.

How do you handle data if we terminate services?
Data return, retention and deletion are governed by the service agreement, Business Associate Agreement and applicable requirements. Confirm the available export format and data-handling responsibilities with the account and compliance teams before termination.

What happens if there's a security incident?
Incident handling and notification responsibilities follow the applicable Business Associate Agreement, service agreement and legal requirements. Contact the compliance team for the notification provisions relevant to your engagement.

Where is my data physically stored?
Ask our compliance team to confirm where engagement data is stored, who may access it, and whether access occurs from another country. Storage locations, authorized access and any subcontractor arrangements should be addressed in the engagement’s security review.

Last Updated: Aug 20, 2026 | Next Review: Dec, 2026
For questions about our security practices, contact digital@dastifysolutions.com