Responsibilities are defined in writing, not on this page. Every clinic signs a Business Associate Agreement with us before onboarding. That agreement — not this page — governs how PHI is handled and where responsibility sits between your clinic and FITWithRCMC.
If we become aware of a security incident affecting your Clinic's data, we will notify you without unreasonable delay, consistent with the notification timelines and process set out in your signed BAA. Specific breach notification obligations and timelines are governed by that agreement, not by this page.
For security or compliance questions, contact [email protected].