We've been seeing more vendors, customers, and prospects asking about HIPAA compliant email marketing services. Since Paubox is a Business Associate to thousands of customers, we’ve been wondering if they are able to use Interspire in a HIPAA compliant manner.
We know the HIPAA industry is vast, so we can empathize with just how many people need to use cloud services in this sector. Today we will determine if Interspire offers HIPAA compliant email marketing service or not.
Interspire markets itself as an all-in-one email marketing software that includes tools to create, send, track and profit from email marketing.
What is a Business Associate?
A Business Associate is a person or company that performs certain functions or activities that involve the use or disclosure of protected health information for a Covered Entity. In a nutshell, the role of a Business Associate is to help Covered Entities comply with the HIPAA Privacy Rule. Since Interspire appears to be a solution that's downloaded and installed on-premise, it does not seem to store protected health information (PHI) on behalf of Covered Entities. Read full article: What does it mean to be a Business Associate?
Business Associate Agreement provisions
If a Business Associate provides services to a Covered Entity, then a Business Associate Agreement (BAA) must be in place. A BAA is a written contract between a Covered Entity and a Business Associate and is required by law for HIPAA compliance. At a minimum, a Business Associate Agreement contains 10 provisions.
Read full article: Business Associate Agreement Provisions
Interspire and the Business Associate Agreement
We checked the Interspire site for mention of their ability to sign a Business Associate Agreement. We could not find any mention of PHI, Business Associate Agreement, Business Associate, or even a Terms of Service page. We did however, notice most of the screenshots on their site were taken back in 2008.
The image below is a prime example:
Lastly, we were able to confirm Interspire is an on-premise solution via a page called Hosted vs Download.
Does Interspire offer HIPAA Compliant Service?The Business Associate Agreement (BAA) is a key component to HIPAA compliance between a Covered Entity and a Business Associate. We were able to learn the following about Interspire:
- It's an on-premise solution, which means the customer is responsible for buying and maintaining the hardware it's installed on.
- Interspire does not store customer information such as PHI in their cloud.
- Interspire's solution does not provide secure email encryption.
Conclusion: Interspire does not appear to fall into the category of a Business Associate, which would then trigger the need for a Business Associate Agreement. Their solution however, is not capable of providing encrypted email. It's our conclusion that by itself, Interspire is not capable of encrypting email and is therefore not a HIPAA compliant email solution.