IMP · Interpretation Management Platform

Security & HIPAA Compliance Overview

How IMP protects agency, interpreter, client, and consumer data — stated plainly. Each control is labeled by where it comes from: engineered into IMP, inherited from our audited infrastructure providers, or part of our active compliance program. We would rather show you an honest map than a wall of green checkmarks.

Prepared July 2026 · Frederick Interpreting Agency / IMP
Built into IMP Inherited from audited infrastructure In progress — compliance program

"Inherited" controls run on SOC 2–audited managed cloud platforms and are configured and verified by IMP. Our subprocessor list is provided under NDA or BAA. HIPAA citations reference 45 CFR Part 164.

Scope of HIPAA-covered services

IMP's HIPAA program covers the scheduling core: appointments and records, the agency/interpreter/client portals, and human-interpreter VRI and OPI calling. For covered customers, IMP executes a Business Associate Agreement and maintains corresponding agreements with the infrastructure subprocessors that store or transmit PHI.

Explicitly outside PHI scope today: AI real-time translation and AI document intake. These features must not be used with protected health information until their vendor agreement chain is complete (planned Phase 2). HIPAA-tier customers receive this boundary in writing, and it is enforced in onboarding guidance.

Access Management & Tenant Isolation

164.308(a)(4) · 164.312(a)Built into IMP
Information is available only to authorized users

Encryption & Decryption

164.312(a)(2)(iv) · 164.312(e)Inherited
Data encrypted in transit and at rest

Key Management

164.312(e)(2)Inherited
Encryption keys protected and rotated

Logging & Audit Controls

164.312(b)Built into IMP
Activity recorded and reviewable

Formal log-retention schedule and a customer log-request procedure are being documented as part of the compliance program (see Administrative Safeguards).

Monitoring

164.308(a)(1)(ii)(D)Inherited + built
Systems watched for failure and misuse

Security Incident Management

164.308(a)(1)(ii) · 164.308(a)(6)In progress
Incidents identified, escalated, remedied, documented

Backup & Recovery

164.308(a)(7)Inherited
Data survives failure

Business Associate Agreements

164.308(b) · 164.314(a)In progress
The agreement chain that makes compliance real

Administrative Safeguards

164.308In progress
The people-and-paper half of HIPAA

We list this honestly as in progress. Vendors who claim complete HIPAA compliance without an administrative program are describing their servers, not their obligations.