Trust your sensitive data to Toloka with HIPAA compliance

Toloka Team
by Toloka Team
Image

Subscribe to Toloka News

Subscribe to Toloka News

Data privacy and security is always top of mind at Toloka. This year we've renewed our ISO/IEC 2700 status and extended it with ISO/IEC 27701 certification. However, companies that collect or label personal health information face stringent requirements for handling this sensitive category of data. We are happy to announce that Toloka is also compliant with HIPAA to safely manage health data.

This blog post will explore why HIPAA compliance is essential and how Toloka ensures maximum security.

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a United States federal law formulated to protect the privacy and security of individuals' medical records and other personal health information. The law's main objective is to prevent healthcare fraud, ensure that all protected health information (PHI) is appropriately secured, and restrict access to health data to authorized individuals. Organizations that handle PHI must secure the data by implementing measures such as encryption, access control, authentication, audit trails, and more.

Under this law, Toloka plays the role of “business associate” — an entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity.

Medical data labeling with confidence

Now that we've confirmed HIPAA compliance, you can trust Toloka with healthcare-related data labeling projects and rest assured that your data is safe. We have reviewed our security practices and conducted a mapping between HIPAA requirements and controls from ISO 27001 and 27701. Our procedure for projects involving PHI includes a consent form for data collection tasks and a Business Associate Agreement, as required by HIPAA regulations.

You can be confident that Toloka operates a secure platform for storing and transmitting sensitive categories of data while staying compliant with HIPAA policies.

How Toloka ensures maximum security

Personal health data can be extra sensitive. We focus on several important steps to protect PHI on the Toloka platform.

Annotator management

For data labeling tasks that involve PHI, we don't recommend using our public crowd of Tolokers. Instead, we carefully select annotators from our team of vetted experts and BPOs. Each annotator signs a non-disclosure agreement, where they agree to preserve the strict confidentiality of the data they handle and accept responsibility for non-compliance. We impose strict requirements for data management and monitor the data labeling process.

Access control

Our access control policy governs our internal operations. The policy follows the Principle of Least Privilege, ensuring that access is granted only when essential for specific tasks. The use of unique user IDs is mandated both internally and externally, with personalized accounts in Azure Active Directory. Employees use Single Sign-On (SSO) for authentication using Toloka credentials. In addition, Role-Based Access Control (RBAC) ensures that any action is granted only after permission verification.

Encryption

We always encrypt all personal data to prevent unauthorized access. All data entrusted to us is stored using Azure Encryption.

For a more detailed look at how we do privacy and security, please refer to our security center.

Learn more
Article written by:
Toloka Team
Toloka Team
Updated: 

Recent articles

Have a data labeling project?

Take advantage of Toloka technologies. Chat with our expert to learn how to get reliable training data for machine learning at any scale.
Fractal

More about Toloka

  • Our mission is to empower businesses with high quality data to develop AI products that are safe, responsible and trustworthy.
  • Toloka is a European company. Our global headquarters is located in Amsterdam. In addition to the Netherlands, Toloka has offices in the US, Israel, Switzerland, and Serbia. We provide data for Generative AI development.
  • We are the trusted data partner for all stages of AI development–from training to evaluation. Toloka has over a decade of experience supporting clients with its unique methodology and optimal combination of machine learning technology and human expertise. Toloka offers high quality expert data for training models at scale.
  • The Toloka team has supported clients with high-quality data and exceptional service for over 10 years.
  • Toloka ensures the quality and accuracy of collected data through rigorous quality assurance measures–including multiple checks and verifications–to provide our clients with data that is reliable and accurate. Our unique quality control methodology includes built-in post-verification, dynamic overlaps, cross-validation, and golden sets.
  • Toloka has developed a state-of-the-art technology platform for data labeling and has over 10 years of managing human efforts, ensuring operational excellence at scale. Now, Toloka collaborates with data workers from 100+ countries speaking 40+ languages across 20+ knowledge domains and 120+ subdomains.
  • Toloka provides high-quality data for each stage of large language model (LLM) and generative AI (GenAI) development as a managed service. We offer data for fine-tuning, RLHF, and evaluation. Toloka handles a diverse range of projects and tasks of any data type—text, image, audio, and video—showcasing our versatility and ability to cater to various client needs.
  • Toloka addresses ML training data production needs for companies of various sizes and industries– from big tech giants to startups. Our experts cover over 20 knowledge domains and 120 subdomains, enabling us to serve every industry, including complex fields such as medicine and law. Many successful projects have demonstrated Toloka's expertise in delivering high-quality data to clients. Learn more about the use cases we feature on our customer case studies page.