HIPAA, HEALTH DATA, AND SECURE SYSTEMS
MORPHD takes the privacy and security of health information seriously.
MORPHD’s founder has completed HIPAA privacy and security training and maintains documentation of that training.
Carepatron
MORPHD uses Carepatron, a HIPAA-compliant practice-management and health-record platform, to collect, maintain, and process sensitive health information.
Carepatron is used for information such as:
Biological Assessment™ responses
Health and family history
Symptoms and health concerns
Medications and supplements
Laboratory results and biomarker information
Consultation and progress notes
Personalized program information
Secure client communications
Progress Check-In™ responses
MORPHD uses Carepatron under its applicable privacy, security, and Business Associate Agreement provisions when required.
Sensitive health information should be submitted only through Carepatron or another secure system specifically approved by MORPHD.
Public Website and MORPHD Snapshot™
The public MORPHD website and general contact forms are not intended for submitting medical records, laboratory reports, diagnoses, medication lists, or other detailed clinical information.
The MORPHD Snapshot™ is a short educational questionnaire that helps identify a possible Gut, Metabolic, or Combined area of focus. It is not a medical intake, diagnostic tool, or substitute for professional medical care.
Do not upload or submit detailed clinical information through the MORPHD Snapshot or general website forms.
MORPHD’s HIPAA Role
MORPHD LLC provides health-program infrastructure, education, assessments, and wellness-related services.
The use of HIPAA-compliant technology and completion of HIPAA training do not automatically make an organization a HIPAA-covered entity. MORPHD’s obligations depend on its role in a particular service or relationship.
When MORPHD creates, receives, maintains, or transmits Protected Health Information on behalf of a HIPAA-covered entity or another Business Associate, MORPHD will handle that information in accordance with:
Applicable HIPAA requirements
The relevant Business Associate Agreement
MORPHD privacy and security procedures
Other applicable privacy and data-security laws
Licensed healthcare providers remain responsible for medical decisions, diagnosis, treatment, prescribing, and clinical documentation within their scope of practice.
MORPHD limits access to sensitive health information to authorized individuals who require access to provide or support the requested services.

