This post is about CCPA compliance (including data deletion requests) and Paubox Marketing, our HIPAA compliant email marketing solution.
See Related: CCPA: How California’s new privacy law impacts healthcare
See Related: HIPAA Compliant Email: The Definitive Guide
As it relates to data deletion requests, consumers may request that businesses delete personal information they collected from them. These businesses are also required to tell their service providers to do the same.
In the aforementioned case of the pharmacy startup, the service provider would be us (Paubox). It should be noted however, there are exceptions that allow businesses to keep consumers' personal information.
Upon request, Paubox will sign a Data Processing Addendum (DPA) with paid customers. Section 6 (Data Subject Rights) of the Paubox DPA states:
Customer is responsible for responding to any Data Subject requests relating to Customer Personal Data (“Requests”). If Paubox receives any Requests during the term, Paubox will advise the Data Subject to submit the request directly to Customer or the appropriate Controller. Paubox will provide Customer with self-service functionality or other reasonable assistance to permit Customer to respond to Requests.
In a nutshell, this means Paubox will provide paid customers with the appropriate level of support to help them comply with data deletion requests from their consumers (end users).
Prior to its launch, healthcare providers were stuck with generic messaging because it was impossible to personalize email with patient information without violating HIPAA regulations.
Now you can send your patients personalized messages that include PHI using our HIPAA compliant email marketing service, Paubox Marketing.
Paubox Marketing is HITRUST CSF certified and is free to use for up to 100 contacts. The free plan also includes a business associate agreement.