HIPAA Privacy & Security Policy

Version: 1.0
Effective Date: July 25, 2026
Organization: SoftEd 21, S.L. (CTO Plus Team)


1. Purpose

SoftEd 21, S.L. (CTO Plus Team) is committed to protecting the confidentiality, integrity, and availability of Protected Health Information (PHI) and complying with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), including the Privacy Rule, Security Rule, and Breach Notification Rule.

This policy establishes the administrative, physical, and technical safeguards used to protect PHI when developing, hosting, supporting, or maintaining software systems for healthcare organizations.


2. Scope

This policy applies to:


3. Definitions

Protected Health Information (PHI)
Any individually identifiable health information maintained or transmitted in any form.

Electronic Protected Health Information (ePHI)
PHI stored or transmitted electronically.

Workforce Member
Any employee, contractor, intern, or consultant with access to PHI.


4. Compliance

SoftEd 21, S.L. (CTO Plus Team) complies with:


5. Minimum Necessary Principle

Access to PHI is limited to the minimum amount necessary to perform assigned job responsibilities.

Employees may only access:


6. Administrative Safeguards

SoftEd 21, S.L. (CTO Plus Team) implements the following administrative safeguards.

6.1 Risk Assessment

Regular security risk assessments are performed to identify:

Risks are documented and remediation plans tracked.

6.2 Workforce Training

Personnel receive training covering:

Training is provided upon hire and periodically thereafter.

6.3 Sanction Policy

Violations of this policy may result in:

6.4 Business Associate Agreements

SoftEd 21, S.L. (CTO Plus Team) enters into Business Associate Agreements when acting as a Business Associate before handling customer PHI.


7. Access Control

Access to systems containing PHI is controlled through:

Access is revoked immediately when employment or contracts terminate.


8. Authentication

Passwords must:

Administrative accounts require MFA whenever available.


9. Technical Safeguards

Encryption

PHI is protected using encryption:

Data in Transit

Data at Rest

Logging

Systems handling PHI maintain audit logs for:

Logs are protected from unauthorized modification.

Monitoring

Security monitoring includes:


10. Physical Safeguards

SoftEd 21, S.L. (CTO Plus Team) uses cloud-first infrastructure and secure office practices.

Safeguards include:


11. Secure Software Development

Software handling PHI follows secure development practices including:

Production changes follow documented deployment procedures.


12. Data Retention

PHI is retained only as required by:

Data is securely deleted when retention periods expire.


13. Backup and Recovery

Systems containing PHI are protected through:


14. Incident Response

Security incidents involving PHI must be reported immediately.

Incident response includes:


15. Breach Notification

If a breach involving unsecured PHI is confirmed, SoftEd 21, S.L. (CTO Plus Team) will:


16. Vendor Management

Third-party vendors with potential access to PHI are evaluated for security controls before use.

Where appropriate:


17. Remote Work

Personnel working remotely must:


18. Mobile Devices

Devices accessing PHI should:


19. Customer Responsibilities

Customers remain responsible for:


20. Workforce Responsibilities

All workforce members must:


21. Policy Review

This policy is reviewed:


22. Contact

Questions regarding this policy may be directed to:

Privacy Officer
SoftEd 21, S.L. (CTO Plus Team)
Paseo Las Azucenas 18A, Marbella, 29602, Malaga, Spain
Email: privacy@ctoplusteam.com


Document Control

Document Title: HIPAA Privacy & Security Policy
Version: 1.0
Effective Date: July 25, 2026
Organization: SoftEd 21, S.L. (CTO Plus Team)
Classification: Internal / Customer Available