Project

General

Profile

Tingg Insight HIPAA Compliance Scope and Applicability » History » Version 1

rashmita rout, 12/23/2025 05:34 PM

1 1 rashmita rout
h1. Tingg Insight HIPAA Compliance Scope and Applicability
2
3
*Product:* Tingg Insight
4
*Platform:* Tingg Platform
5
*Version:* v1.0
6
*Status:* Draft
7
*Owner:* Product / Compliance
8
*Last Updated:* [Date]
9
 
10
---
11
 
12
h2. 1. Purpose
13
 
14
This document defines the *scope and applicability of HIPAA compliance* for the *Tingg Insight* product, which operates as a module within the broader *Tingg Platform*.
15
 
16
The purpose of this document is to:
17
 
18
* Clearly establish what is *in scope* and *out of scope* for HIPAA
19
* Prevent ambiguity during development, testing, and audits
20
* Serve as the *authoritative boundary document* for all HIPAA-related work
21
 
22
This document must be read in conjunction with:
23
 
24
* HIPAA Compliance BRD
25
* HIPAA Compliance Epics & User Stories
26
* HIPAA Test & Evidence Plan
27
 
28
---
29
 
30
h2. 2. Regulatory Framework
31
 
32
The following HIPAA regulations are applicable to Tingg Insight *within the defined scope*:
33
 
34
* HIPAA Privacy Rule (45 CFR §164.500–534)
35
* HIPAA Security Rule (45 CFR §164.302–318)
36
  ** Administrative Safeguards
37
  ** Technical Safeguards
38
  ** Physical Safeguards *(limited applicability – see exclusions)*
39
 
40
*Note:* Tingg Insight is designed to be *HIPAA-eligible*, not inherently HIPAA-certified. Compliance depends on correct configuration and operational practices by the customer.
41
 
42
---
43
 
44
h2. 3. In-Scope Products & Modules
45
 
46
h3. 3.1 In-Scope Product
47
 
48
* Tingg Insight
49
 
50
Tingg Insight is a survey, assessment, and insights module that may collect, process, store, or analyze data that qualifies as *Protected Health Information (PHI)* when configured for healthcare-related use cases.
51
 
52
---
53
 
54
h3. 3.2 Out-of-Scope Products
55
 
56
The following Tingg Platform products are *explicitly out of HIPAA scope*:
57
 
58
* Tingg Career (ATS / Recruitment)
59
* Tingg KM (Knowledge Management)
60
* Marketing websites, landing pages, blogs
61
* Admin portals not directly interacting with PHI
62
* Experimental or beta modules not explicitly approved
63
 
64
---
65
 
66
h2. 4. In-Scope Features (Tingg Insight)
67
 
68
The following Tingg Insight features are *within HIPAA scope when used to handle PHI*:
69
 
70
* Survey and assessment response collection
71
* Storage of responses containing PHI
72
* Analytics and reporting dashboards derived from PHI
73
* User authentication and authorization for PHI access
74
* Audit logging related to PHI access and modification
75
* Data export features involving PHI (CSV, API, integrations)
76
 
77
*Important:* Feature inclusion in scope depends on *actual usage*.
78
A feature may be in scope for one customer and out of scope for another.
79
 
80
---
81
 
82
h2. 5. Out-of-Scope Features
83
 
84
The following features are *explicitly excluded from HIPAA scope*:
85
 
86
* Anonymous surveys with no PHI fields
87
* Static content pages (instructions, help text, thank-you pages)
88
* UI theming and branding configuration
89
* Survey templates without PHI
90
* Client-side analytics not tied to identifiable individuals
91
* Non-production environments used for demos or marketing
92
 
93
---
94
 
95
h2. 6. In-Scope Data (PHI Definition)
96
 
97
For Tingg Insight, *Protected Health Information (PHI)* includes, but is not limited to:
98
 
99
* Names, email addresses, phone numbers when linked to health data
100
* Medical conditions, symptoms, or diagnoses
101
* Treatment-related survey responses
102
* Identifiers such as patient IDs or appointment references
103
* Any combination of identifiers and health-related information
104
 
105
PHI determination is *contextual* and depends on:
106
 
107
* Survey configuration
108
* Question types
109
* Customer use case
110
 
111
---
112
 
113
h2. 7. Out-of-Scope Data
114
 
115
The following data types are *out of HIPAA scope*:
116
 
117
* Fully anonymous responses with no identifiers
118
* Aggregated or de-identified analytics
119
* System metadata (timestamps, request IDs) unless linked to PHI
120
* Platform operational metrics
121
* Billing and subscription data
122
 
123
---
124
 
125
h2. 8. In-Scope Users & Roles
126
 
127
The following user roles may have *access to PHI* and are therefore in scope:
128
 
129
* Customer administrators
130
* Authorized internal platform administrators
131
* Support personnel with approved PHI access
132
* Compliance or audit users
133
 
134
Access to PHI is governed by:
135
 
136
* Role-based access control (RBAC)
137
* Least privilege principles
138
* Audit logging
139
 
140
---
141
 
142
h2. 9. Out-of-Scope Users
143
 
144
The following users are *not considered in scope*:
145
 
146
* Survey respondents (data subjects)
147
* Marketing users
148
* Sales users
149
* Unauthenticated public users
150
* Internal users without PHI access
151
 
152
---
153
 
154
h2. 10. Environment Scope
155
 
156
h3. In-Scope Environments
157
 
158
* Production environments handling real customer data
159
* Disaster recovery and backup systems containing PHI
160
 
161
h3. Out-of-Scope Environments
162
 
163
* Local development environments
164
* Test or staging environments with synthetic data
165
* Demo environments
166
* Developer sandboxes
167
 
168
---
169
 
170
h2. 11. Shared Responsibility Model
171
 
172
HIPAA compliance for Tingg Insight follows a *shared responsibility model*.
173
 
174
h3. Tingg (Platform Owner) Responsibilities
175
 
176
* Application-level security controls
177
* Access control mechanisms
178
* Audit logging
179
* Encryption at rest and in transit
180
* Secure software development practices
181
 
182
h3. Customer Responsibilities
183
 
184
* Correct configuration of surveys
185
* Determination of PHI fields
186
* User access management
187
* Operational policies and procedures
188
* Business Associate Agreement (BAA) management
189
 
190
---
191
 
192
h2. 12. Assumptions & Constraints
193
 
194
* Tingg Insight is HIPAA-eligible, not automatically HIPAA-compliant
195
* Compliance depends on customer usage and configuration
196
* This scope may evolve based on:
197
  ** New features
198
  ** Regulatory changes
199
  ** Customer requirements
200
 
201
---
202
 
203
h2. 13. Scope Change Management
204
 
205
Any change to this scope must:
206
 
207
* Be reviewed by Product and Compliance
208
* Be documented as a new version
209
* Trigger a review of impacted Epics, Stories, and Tests
210
 
211
---
212
 
213
h2. 14. Approval
214
 
215
|*. Role |*. Name |_. Date |
216
| Product Owner | [TBD] | |
217
| Compliance Owner | [TBD] | |
218
| Engineering Lead | [TBD] | |
219
 
220
---