For administrators

Questions we expect you to ask.

Complete sentences. Sources at the bottom. This is not legal advice. Before you buy, have your own attorney read the order form and our hosting memo. The memo is a draft. Health-privacy counsel has not signed it yet. We will say so here when that happens. We will not pretend it already has.

Is SurgeryHub HIPAA compliant?

We do not use that phrase. HIPAA compliance is a program a covered entity runs for protected health information, not a label that comes with a website (U.S. Department of Health and Human Services [HHS], n.d.-a). The pain center or surgery center is the covered entity. They treat people. The packet is theirs.

SurgeryHub hosts public pages: hours, services, who is on staff, an accreditation mark. A name on a door plus “we do knee injections” is not, by itself, a patient’s designated record set. A name plus last meal time, allergies, and a signature on our disk would be protected health information if we kept it (45 C.F.R. § 160.103). We are built so that packet never sits on our computers. That is a design choice. It is not a government certification.

Talk to an attorney who does health privacy, not only a general business lawyer, before you rely on this for a survey or a payer audit.

Will you sign a business associate agreement?

Not for this product, unless counsel tells us we must, or unless you ask us to start keeping the packet. A business associate is someone who creates, receives, maintains, or transmits protected health information for a covered entity (HHS, n.d.-a). Cloud companies that store electronic protected health information are business associates even when they cannot read the file (HHS, n.d.-b). We are not offering to store that file.

The “conduit” exception (postal service, some internet carriers) is narrow. We do not claim it for stored forms. We claim we do not store the forms. If a packet lands on SurgeryHub by mistake, our draft memo says we stop, we do not use it, we try to delete it, and we do not pretend this SKU is now a records system (SurgeryHub, 2026).

If you need a vendor who keeps charts in their cloud and signs a business associate agreement, that is a different company and a different price. Have your attorney say which one you are buying.

Where does the patient packet go?

The patient fills history and last meal time at home. They view consent language. They do not sign anesthesia consent until they have met the certified registered nurse anesthetist, the anesthesiologist assistant, or the physician anesthesiologist. When they finish, the packet is saved on their computer. SurgeryHub does not operate a database or a cache for that file. There is no continuous connection that holds the packet at our office. If the office computer is turned off, or if no one is signed in at the office, the packet remains on the patient’s device. When a staff member signs in, or leaves an office computer open to receive packets while that computer is on and connected, the packet can be sent. It is not stored in a SurgeryHub mailbox.

We may check that the public website is up. We do not POST a test chart. We do not read names, meals, or signatures.

Is the private path encrypted?

When a send happens, the patient’s browser posts the packet only to an https address the clinic owns. This site is served over https. Browsers will not post from an https page to a plain http address. The product also refuses a webhook that is not https, so a mis-typed http address does not send. That is TLS from the patient’s computer to the clinic’s endpoint, the same class of encryption used for online banking. SurgeryHub’s computers are not in the middle. We cannot read the packet. We do not keep a copy. We could not produce one under subpoena, because none exists on our side.

If the send fails, the packet stays on the patient’s computer. Nothing is written to SurgeryHub. We may check that a published path answers, with an empty GET. That tells us the path is up. It does not tell us that a named patient’s packet arrived.

Treat the endpoint address like a password. Anyone who has that URL can post to it unless your endpoint checks what arrives. On the patient’s computer, the saved packet is protected by that computer’s login, not by extra encryption at rest. A shared waiting-room computer is the clinic’s responsibility.

We say the path is encrypted in transit to your endpoint. We do not use “secure” as a blanket word. We do not call this HIPAA compliant. Ask your attorney. Read the counsel draft.

What do your legal drafts say today?

The working memo is unlisted for counsel at /counsel. It is a draft. It has been looked at as a business document. It has not been signed by a health-privacy specialist. We have a startup business attorney, access to a wealth-management attorney, and a colleague who practices Department of Labor work. None of those three, by title, is “our HIPAA lawyer.” We are retaining specialized counsel. Until that person signs, do not tell a surveyor that SurgeryHub’s lawyers blessed this.

The draft, in short, says:

  • We host public pages, DNS, and the certificate.
  • The packet waits on the patient’s computer, not ours.
  • No refund after export (the copy is open, like a product key).
  • Invoices go to the practice. They are not a patient’s copay with a diagnosis on the line.
  • If protected health information or a client file hits us, that is a stop, not a new feature.

Who should I talk to before I buy?

Your attorney. Preferably one who has read the Health Insurance Portability and Accountability Act privacy and security rules for vendors, not only employment or wealth work. Show them this page, the counsel draft, and pricing. If they want a business associate agreement, call us — that is option B on the memo, and it is not this price.

Is this an electronic health record?

No. There is no patient database on our side. Staff print a paper packet on the clinic computer. The anesthesia record is a paper chart, front and back. We are not a hospital system, not a billing company, and not a place to store years of visits.

Do we have to use your forms?

No. Setup includes wiring the packet your organization already uses: history, last meal time, consents patients view before they arrive. A tenant dentist does not have to share a pain-center clipboard. We do not sell a separate form-builder. Putting your sheets in the portal is part of the price. Putting your sheets in the portal is included in the setup price. The completed packet remains on the patient’s computer until the office is using the platform. We do not keep the file.

What is the patient education library?

It is a searchable set of short procedure cards at about a tenth-grade reading level. Human nurses and anesthesia providers write and review the wording. The same text prints on the after-visit sheet with the anesthesia record. The catalog grows as the platform grows. Centers on the monthly retainer receive those updates at no extra charge for as long as they stay. If you export the site, you keep the copy from that day. You do not keep a live feed after you leave.

This is teaching, not a chart. It does not replace the talk with the clinician before any medicine is given. Ideas were checked against public sources such as NYSORA spine-injection topics and AAPM&R spinal procedures. Those groups do not endorse SurgeryHub. See the library.

You use Stripe. Is that allowed?

Invoices go to your center ($7,000 setup, $249 a month if we still host). We put a business name and a billing email there. We do not put a patient’s name, procedure, or last meal time on the invoice. Keep clinical detail out of the payment description. Your attorney should confirm that the payment-processing carve-out fits how you buy (HHS, n.d.-a).

What if we export and skip the month?

After $7,000 is paid, we can hand you the site files. You host them. We stop the certificate and the night watch. Once those files leave, there is no refund. Same idea as opening a software license. Most centers will still want the $249 month. That is a choice, not a requirement.

The address depends on which one you picked. On your-center.surgeryhub.care you give the address up, because that domain is ours. On a domain you registered, export moves where the pages are served and nothing else — your cards, your listings, and your email keep working.

Can we use our own domain instead of a subdomain?

Yes, and most centers should. A subdomain is included and works on day one. Your own domain is an added line on the setup invoice; tell us the domain and we quote it before you sign.

We buy it on your behalf and register it in your name. While you are on the $249 month we pay the yearly fee, up to $24 a year, and we renew it so it does not lapse. Names that cost more than that are billed at the difference, at cost, and we quote a premium name before we buy anything.

You are the registrant from day one. If you export or stop the month, we transfer the domain to your registrar account at no charge, or you take over the yearly bill. We do not keep the domain your practice depends on. That is the same reason we do not keep your packets.

If you already own a domain, bring it. We point it at your site and there is no domain line on your invoice.

Can you set up email on our domain?

We can do the setup. We do not run the mailbox. You buy the mail service in your own account, and you sign whatever agreement that provider offers for health data. We configure the records, the addresses, and the sending so mail from your practice is delivered and not treated as spam. Then we hand it over.

We do not hold a login to your mail after setup, and we do not receive your mail. A mailbox keeps what it is sent, and patients will send health information to a clinic address whether or not you invite it. Keeping that on your side of the line is the point. Ask your attorney how your practice should handle patient email before you publish the address.

This is also why an address that matches your site matters. front-desk@your-center.surgeryhub.care reads like something a patient should not trust.

Can we put ads or a chat bubble on the site?

Not if the tool sends a patient’s form, name, or “I need a lumbar injection” to a company that will not sign for health data. A marketing pixel on a public brochure is one fact pattern. A chat that collects history is another. The draft memo says you will not wire tools that dump the packet to SurgeryHub or to a third party we did not approve (SurgeryHub, 2026). Ask your attorney before you drop a pixel on a page that sits next to intake.

What about the jobs board?

jobs.surgeryhub.care is a vacancy board for clinicians and facilities. It is not a patient chart. Do not post protected health information there. A shift listing is not a last meal time.

You mentioned law firms.

Same pattern: public site, packet to the firm’s endpoint, no client files on SurgeryHub. Privilege stays at the firm. That vertical is not for sale until counsel marks the memo. SurgeryHub is the first template.

References

Citations follow the idea of APA (7th): author, year, title, source. They are for administrators and their lawyers, not a journal submission. Nothing here is a legal opinion of SurgeryHub.