How Global Well BHSC handles protected health information (PHI) in our US engagements.
Last updated · 21 July 2026
Global Well BHSC is a consulting firm. When engaged by a US Covered Entity (hospital, clinic, health plan, or provider organisation) in a role that involves Protected Health Information (PHI), we act as a Business Associate under the Health Insurance Portability and Accountability Act (HIPAA), 45 CFR Parts 160 and 164.
Before receiving or accessing PHI, we execute a signed Business Associate Agreement with the Covered Entity or upstream Business Associate. The BAA governs permitted uses, disclosures, safeguards, subcontractor obligations, breach notification, and return or destruction of PHI at termination.
Wherever possible, we work with de-identified data under 45 CFR §164.514 (Safe Harbor or Expert Determination). Consulting deliverables, insights, and case studies are de-identified before publication.
In the event of a security incident involving PHI, we will notify the Covered Entity without unreasonable delay and no later than the timeline specified in the executed BAA, consistent with 45 CFR §164.410.
To request a BAA, our HIPAA policies summary, or to report a suspected incident, email hello@globalwellbhsc.com or call +1 (917) 747-8443. See our Privacy Policy and NDPR statement for related detail.