HIPAA Compliance
Scope
This page describes how the LODHI-A website and clinical instrument relate to the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations. It is intended to help clinicians understand their obligations when using the LODHI-A in clinical practice.
The LODHI-A Website Does Not Process PHI
The LODHI-A website (lodhi-a.com) does not collect, store, transmit, or process protected health information (PHI) in any form. The Request Access form collects only clinician professional information (name, email, role, country, and optional NPI number). No patient names, dates of birth, medical record numbers, diagnoses, or any other individually identifiable health information is entered into or processed by this website.
The LODHI-A Instrument Is a Paper/PDF Clinical Tool
The LODHI-A is distributed as a clinical interview guide (print or PDF format) that clinicians administer within their own practice environments. It functions like any other clinical form or structured interview protocol — the clinician records patient responses in their own medical record system, using their own HIPAA-compliant workflows. The LODHI-A instrument itself does not include any digital data collection, electronic transmission, or cloud-based storage of patient information.
Clinician Responsibilities
Clinicians who use the LODHI-A are responsible for ensuring that all patient data generated during administration is handled in compliance with HIPAA and any applicable state or international privacy regulations within their own practice environment. This includes storing completed interview records in HIPAA-compliant electronic health record (EHR) systems or secure physical files, ensuring that any notes, scoring sheets, or collateral forms are treated as part of the patient’s medical record, applying their practice’s existing HIPAA policies to LODHI-A documentation just as they would to any other clinical assessment tool, and ensuring that telemedicine sessions in which the LODHI-A is administered comply with their telehealth platform’s HIPAA requirements.
Business Associate Agreements
Because the LODHI-A website does not access, store, or transmit PHI, a Business Associate Agreement (BAA) between the clinician’s practice and LODHI-A Clinical Instruments is not required for use of the website or the clinical instrument in its current form. If future digital features are introduced that involve processing of PHI (such as an electronic scoring platform), we will implement appropriate BAAs, encryption, access controls, and compliance documentation before those features are made available.
Future Digital Development
As the LODHI-A platform evolves, any features that involve electronic collection or transmission of clinical data will be designed with HIPAA compliance as a foundational requirement. This includes end-to-end encryption, role-based access controls, audit logging, and formal security risk assessments. This page will be updated to reflect the compliance posture of any new digital capabilities.
Contact
Clinicians with questions about HIPAA compliance in the context of LODHI-A use should contact us through the request access form on our homepage.
Last updated: September 2026