Last updated:

HIPAA & PHI Guidance

Using ResiOnboarding Responsibly

ResiOnboarding is designed to support senior living move-in coordination, resident onboarding, first-90-day engagement, satisfaction tracking, and operational task management. Standard ResiOnboarding accounts are intended for non-clinical, non-PHI use.

This page provides general guidance to help users understand what types of information should and should not be entered into the platform unless the organization has a signed Business Associate Agreement with ResiOnboarding and the account has been configured and authorized for HIPAA-related use.

This page is for general educational purposes only and does not provide legal, clinical, regulatory, compliance, or HIPAA advice. Customers should consult their own legal, privacy, compliance, or clinical advisors as needed.

Important No-PHI Reminder

Standard ResiOnboarding accounts are not intended for protected health information, medical records, clinical documentation, or other health-related information.

Do not enter, upload, transmit, or store protected health information (PHI), medical records, diagnoses, medications, physician orders, care plans, clinical notes, hospital discharge information, therapy notes, incident reports containing health details, or other health-related information unless:

  1. Your organization has signed a Business Associate Agreement with ResiOnboarding;
  2. Your account has been configured for HIPAA-related use;
  3. ResiOnboarding has confirmed in writing that the account is authorized for PHI-related workflows; and
  4. Your organization and users follow applicable account, privacy, security, and acceptable use requirements.

What Is PHI?

Protected Health Information, often called PHI, generally refers to individually identifiable health information that relates to a person's health, healthcare, healthcare services, or payment for healthcare services.

In a senior living setting, information may become PHI when it identifies a resident, patient, prospect, staff member, or other person and is connected to health, care, diagnosis, treatment, clinical status, healthcare payment, or related services.

Examples of Information Not to Enter in Standard Accounts

Unless your organization has a signed BAA with ResiOnboarding and your account is authorized for HIPAA-related use, do not enter or upload information such as:

  • Medical records
  • Diagnosis information
  • Medication lists
  • Physician orders
  • Care plans
  • Clinical notes
  • Therapy notes
  • Hospital discharge documents
  • Lab results
  • Immunization records
  • Mental health information
  • Cognitive status details
  • Dementia or memory care diagnosis details
  • ADL assistance needs tied to health or care
  • Fall risk information
  • Behavior notes tied to health or care
  • Incident reports containing injury or health details
  • Insurance or payment information tied to healthcare services
  • Medical record numbers
  • Photos showing wounds, injuries, medical conditions, or clinical care
  • Any other health-related information connected to an identifiable person

Examples of Information Generally Appropriate for Standard Accounts

Standard ResiOnboarding accounts may be used for non-clinical onboarding and resident experience workflows, such as:

  • Move-in task status
  • Unit readiness
  • Welcome call completed
  • Orientation scheduled
  • Dining introduction completed
  • Maintenance readiness
  • Housekeeping readiness
  • Transportation introduction
  • Activity or lifestyle introduction
  • General resident satisfaction score
  • General onboarding feedback without health details
  • Department task assignments
  • First-90-day follow-up reminders
  • Non-clinical resident experience notes

Reminder: Even when using standard accounts, users should avoid entering unnecessary sensitive information and should follow their organization's internal privacy and security policies.

Document Upload Guidance

Users should be especially careful when uploading documents. Standard accounts should not be used to upload medical records, physician forms, care plans, medication lists, hospital discharge documents, clinical assessments, therapy notes, or other documents containing PHI.

If your organization needs to upload health-related documents, contact ResiOnboarding before doing so. PHI-related document workflows require a signed Business Associate Agreement and a HIPAA-configured account.

Free-Text Fields, Notes, Messages, and Surveys

Free-text fields can create privacy risk because users may accidentally type sensitive information. Unless your organization has a signed BAA and authorized HIPAA-configured account, do not enter PHI into:

  • Notes
  • Comments
  • Messages
  • Survey responses
  • Support requests
  • Resident feedback fields
  • Staff follow-up notes
  • Uploaded file descriptions

Use non-clinical language focused on move-in coordination and resident experience.

Use

"Follow up needed regarding move-in orientation."

Avoid

"Resident needs follow-up due to medication issue or recent hospital discharge."

Business Associate Agreements

A Business Associate Agreement, often called a BAA, is a written agreement that may be required when a service provider handles protected health information on behalf of a HIPAA-regulated customer.

ResiOnboarding standard accounts should not be used for PHI. If a customer's workflow requires PHI, the customer must contact ResiOnboarding before submitting such information.

PHI may only be submitted when:

  • A BAA has been signed;
  • The account has been configured and authorized for HIPAA-related use;
  • Appropriate safeguards and account controls are in place; and
  • The customer and users agree to follow applicable requirements.

Nothing on this page replaces or modifies a signed Business Associate Agreement. If a BAA applies, the terms of the BAA will govern the handling of PHI.

Customer and User Responsibilities

Customers and users are responsible for using ResiOnboarding appropriately. This includes:

  • Training users on what should and should not be entered into the platform
  • Managing user access and permissions
  • Preventing unauthorized PHI submission into standard accounts
  • Following internal privacy, security, compliance, and operational policies
  • Reporting suspected unauthorized access, misuse, or improper submission of PHI
  • Consulting legal, compliance, clinical, or regulatory advisors when needed

ResiOnboarding does not control what users choose to type, upload, or submit. Customers are responsible for ensuring that their users follow these guidelines and any applicable agreements.

If You Are Unsure, Do Not Enter It

If you are unsure whether information may be PHI or sensitive health-related information, do not enter it into a standard ResiOnboarding account.

Instead:

  1. Check with your supervisor or organization's compliance/privacy officer;
  2. Review your organization's internal policies;
  3. Contact ResiOnboarding for account configuration guidance; and
  4. Do not upload or submit the information until the proper authorization is confirmed.

Contact ResiOnboarding

If your organization needs PHI-related workflows, HIPAA-configured account options, or a Business Associate Agreement, please contact ResiOnboarding before submitting any protected health information into the platform.

support@resionboarding.com