ZenHub Services
HIPAA Notice
// Last updated May 11, 2026
ZenHub Services LLC acts as a HIPAA Business Associate to the dental practices we serve. This notice is a plain-language summary of how we handle Protected Health Information (PHI). Where this notice and a signed Business Associate Agreement (BAA) differ, the BAA controls.
// Contents
- Our role
- Team structure & data location
- Safeguards
- Use & disclosure
- Breach notification
- Patient rights
- Contact
1. Our role
ZenHub is a Business Associate, not a covered entity. We handle PHI on behalf of dental practices (covered entities) under the scope and conditions defined in each BAA. We do not use PHI for any purpose outside what the BAA permits.
2. Team structure & data location
Our managed specialist team is fully HIPAA-trained and operates under encrypted, role-based access with audit logging. A dedicated channel manager coordinates daily work and is the single point of contact for each practice.
All PHI access is logged. PHI is not stored on personal devices. Access is provisioned and de-provisioned through a documented process tied to engagement status.
3. Safeguards
- HIPAA-trained team members with annual refresher training.
- Encrypted communication channels for all PHI-bearing exchanges.
- Role-based access controls — least-privilege by default.
- No PHI stored outside secure, audited systems.
- Audit logging on all account access; logs reviewed regularly.
- Written incident response and breach-notification procedures.
- BAA executed before any PHI is exchanged.
4. Use & disclosure
We use and disclose PHI only as permitted by the BAA — to perform the services contracted by the practice, to comply with legal obligations, and to manage and administer ZenHub's operations as a Business Associate. We do not use PHI for marketing. We do not sell PHI under any circumstances.
5. Breach notification
In the event of a confirmed breach of unsecured PHI, we will notify the affected practice without unreasonable delay and no later than the timeframes required by HIPAA and the applicable BAA. Our notice will include the scope, cause, mitigation, and corrective actions.
6. Patient rights
Patients should direct requests regarding their PHI (access, amendment, accounting of disclosures, restrictions) to the dental practice that holds the patient relationship. If a practice routes a request to us under their BAA, we respond on their behalf within the timelines required by law.
7. Contact
Privacy & Compliance — ZenHub Services LLC
Email: privacy@zenhubservices.com
A BAA is available on request.