← Back to Compliance Policies

BioFuelHQ Compliance

Data Security Policy

Effective Date: July 22, 2026

This policy summarizes BioFuelHQ security practices for website, intake, admin access, vendors, and records.

1. Security Program

BioFuelHQ uses layered administrative, technical, and physical safeguards designed to protect personal information and health-related information.

Security measures may include HTTPS, access controls, staff roles, secure vendors, audit review, restricted admin access, and secure storage practices.

2. HIPAA-Compliant Vendors

When vendors create, receive, maintain, or transmit PHI/ePHI on behalf of BioFuelHQ or care partners, BioFuelHQ requires a Business Associate Agreement when required by law.

BAA records should be stored outside public website folders.

3. Admin Access

Admin access should be limited to authorized staff only.

Shared logins should not be used. Staff access should be removed when no longer needed.

4. File Uploads

Upload features should restrict file types, block executable files, scan or validate uploads where available, and prevent public access to sensitive files.

Medical files should not be uploaded through general public forms unless the form is part of the secure intake process.

5. Incident Response

BioFuelHQ will investigate suspected security incidents and take appropriate action based on the facts, applicable law, vendor obligations, and patient-safety considerations.

Emergency Notice: BioFuelHQ is not an emergency medical service. If you are experiencing a medical emergency, call 911 or seek emergency medical care immediately.

© 2026 BioFuelHQ. All rights reserved. Website content is for informational purposes only and does not guarantee approval, treatment, prescription, medication access, product access, or eligibility.

Pre-Qualify