This HIPAA Compliance Policy describes how Complete Intake, Inc. safeguards Protected Health Information and supports HIPAA compliant healthcare operations.
Effective Date: January 17, 2026
Complete Intake, Inc., a Delaware corporation ("Complete Intake" or the "Company"), is committed to ensuring the confidentiality, integrity, and availability of all Protected Health Information ("PHI") that we create, receive, maintain, or transmit on behalf of our healthcare agency clients.
This HIPAA Compliance Policy describes our compliance program under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"), as amended by the HITECH Act, and their implementing regulations.
As a provider of AI-powered home health referral management services, Complete Intake acts as a Business Associate to Covered Entities under HIPAA. This policy establishes the administrative, technical, and physical safeguards governing our handling of PHI.
This policy applies to:
Terms used in this policy have the meanings set forth in 45 C.F.R. § 160.103, including:
Complete Intake enters into a Business Associate Agreement ("BAA") with each healthcare client prior to receiving or processing PHI. The BAA governs permitted uses and disclosures of PHI, required safeguards, breach notification responsibilities, and compliance obligations.
All subcontractors that create, receive, maintain, or transmit PHI on behalf of Complete Intake must execute written agreements imposing HIPAA-equivalent obligations. Complete Intake obtains satisfactory assurances that subcontractors will appropriately safeguard PHI.
The platform may process PHI including:
PHI is used or disclosed only as permitted by the applicable BAA and law, including:
Complete Intake applies the minimum necessary standard through system design, access controls, and workflow restrictions.
Complete Intake designates a Privacy Officer and Security Officer responsible for HIPAA compliance oversight.
All workforce members with PHI access receive training upon hire and at least annually, covering:
Including:
Given the AI-enabled nature of the platform, Complete Intake implements additional controls, including:
Physical access to systems and facilities is restricted to authorized personnel.
Including:
Procedures are maintained to identify, mitigate, and document security incidents.
In the event of a breach of unsecured PHI, Complete Intake will:
All breach investigations and responses are documented in accordance with HIPAA.
PHI is retained in accordance with applicable law and client agreements. Default retention for referral data is seven (7) years, unless otherwise required.
PHI is securely destroyed in accordance with NIST media sanitization guidelines when no longer required.
Violations may result in disciplinary action, up to termination.
HIPAA compliance documentation is retained for at least six (6) years.
Retaliation against individuals reporting compliance concerns is strictly prohibited.
Complete Intake conducts ongoing evaluations, including:
For questions or concerns regarding this HIPAA Compliance Policy, please contact:
Privacy Officer
Complete Intake, Inc.
(a Delaware corporation)
2727 LBJ Freeway, Suite 324
Dallas, Texas 75234
Email: [email protected]
Phone: (469) 257-3153
Policy Owner: Chief Privacy Officer
Version: 1.2
Effective Date: January 17, 2026
Last Review: January 10, 2026
Next Review: January 17, 2027

(469) 257 - 3153
2727 LBJ Fwy, Suite 324
Dallas, TX 75234
Disclaimer: In very rare cases, Complete Intake and all its modules can make mistakes. It is the responsibility of the user and organization to verify the accuracy of all information.