Version: 1.0
Effective Date: July 25, 2026
Organization: SoftEd 21, S.L. (CTO Plus Team)
SoftEd 21, S.L. (CTO Plus Team) is committed to protecting the confidentiality, integrity, and availability of Protected Health Information (PHI) and complying with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), including the Privacy Rule, Security Rule, and Breach Notification Rule.
This policy establishes the administrative, physical, and technical safeguards used to protect PHI when developing, hosting, supporting, or maintaining software systems for healthcare organizations.
This policy applies to:
Protected Health Information (PHI)
Any individually identifiable health information maintained or transmitted in any form.
Electronic Protected Health Information (ePHI)
PHI stored or transmitted electronically.
Workforce Member
Any employee, contractor, intern, or consultant with access to PHI.
SoftEd 21, S.L. (CTO Plus Team) complies with:
Access to PHI is limited to the minimum amount necessary to perform assigned job responsibilities.
Employees may only access:
SoftEd 21, S.L. (CTO Plus Team) implements the following administrative safeguards.
Regular security risk assessments are performed to identify:
Risks are documented and remediation plans tracked.
Personnel receive training covering:
Training is provided upon hire and periodically thereafter.
Violations of this policy may result in:
SoftEd 21, S.L. (CTO Plus Team) enters into Business Associate Agreements when acting as a Business Associate before handling customer PHI.
Access to systems containing PHI is controlled through:
Access is revoked immediately when employment or contracts terminate.
Passwords must:
Administrative accounts require MFA whenever available.
PHI is protected using encryption:
Data in Transit
Data at Rest
Systems handling PHI maintain audit logs for:
Logs are protected from unauthorized modification.
Security monitoring includes:
SoftEd 21, S.L. (CTO Plus Team) uses cloud-first infrastructure and secure office practices.
Safeguards include:
Software handling PHI follows secure development practices including:
Production changes follow documented deployment procedures.
PHI is retained only as required by:
Data is securely deleted when retention periods expire.
Systems containing PHI are protected through:
Security incidents involving PHI must be reported immediately.
Incident response includes:
If a breach involving unsecured PHI is confirmed, SoftEd 21, S.L. (CTO Plus Team) will:
Third-party vendors with potential access to PHI are evaluated for security controls before use.
Where appropriate:
Personnel working remotely must:
Devices accessing PHI should:
Customers remain responsible for:
All workforce members must:
This policy is reviewed:
Questions regarding this policy may be directed to:
Privacy Officer
SoftEd 21, S.L. (CTO Plus Team)
Paseo Las Azucenas 18A, Marbella, 29602, Malaga, Spain
Email: privacy@ctoplusteam.com
Document Title: HIPAA Privacy & Security Policy
Version: 1.0
Effective Date: July 25, 2026
Organization: SoftEd 21, S.L. (CTO Plus Team)
Classification: Internal / Customer Available