Is UNOS DonorNet's Waitlist Messaging Portal HIPAA Compliant for Transplant Clinics?

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Is UNOS DonorNet's Waitlist Messaging Portal HIPAA Compliant for Transplant Clinics?

Kevin Henry

HIPAA

August 01, 2026

7 minutes read
Share this article
Is UNOS DonorNet's Waitlist Messaging Portal HIPAA Compliant for Transplant Clinics?

Overview of DonorNet Waitlist Messaging Portal

The DonorNet Waitlist Messaging Portal is designed to help transplant clinics coordinate time‑sensitive communications with organ procurement organizations (OPOs) and partner centers. Messages often include clinical updates, organ offer details, and candidate status information that qualify as Protected Health Information (PHI) and Electronic Protected Health Information (ePHI).

Because the portal transmits and stores ePHI, its use must align with HIPAA. Importantly, HIPAA compliance is not a one‑time “product certification”; it is an ongoing, shared responsibility between the platform provider and your clinic, driven by documented safeguards, a Business Associate Agreement (BAA) when applicable, and disciplined user practices.

HIPAA Compliance Requirements

Under HIPAA, a transplant clinic is a covered entity. Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is typically a business associate and must sign a BAA. The BAA should define permitted uses, required safeguards, subcontractor obligations, breach reporting timelines, and the return or destruction of PHI at termination.

The HIPAA Security Rule requires administrative, physical, and technical safeguards. Practically, you must perform a risk analysis, implement role‑based Access Controls, maintain Audit Controls, train your workforce, and establish incident response and contingency plans. Privacy Rule obligations—such as the minimum necessary standard—apply to all messages and attachments sent through the portal. The Breach Notification Rule governs incident reporting and patient notifications when applicable.

Security Features of DonorNet

Before exchanging ePHI, confirm that the DonorNet Waitlist Messaging Portal implements security controls that support HIPAA alignment. Prioritize the following areas and obtain written confirmation where possible:

  • Access Controls: unique user IDs, least‑privilege, role‑based authorization, timely provisioning and deprovisioning, and session timeouts.
  • Multi‑factor authentication: strong authentication for all privileged and remote access.
  • Audit Controls: immutable, time‑stamped logs for logins, message access, downloads, and administrative actions, with alerting for anomalous activity and export for compliance review.
  • Data Encryption: TLS 1.2+ or TLS 1.3 for data in transit and strong encryption (for example, AES‑256 using FIPS‑validated modules) for data at rest, with documented key management practices.
  • Integrity and transmission protections: hashing/checksums, prevention of message tampering, and safeguards against misrouting.
  • Availability and resilience: backups, disaster recovery objectives (RTO/RPO), geographic redundancy, and tested restore procedures.
  • Data handling safeguards: controls to restrict unnecessary downloads, watermarking or banner reminders, and clear message retention parameters.

If any of these safeguards are absent or cannot be verified, treat the risk as unresolved and escalate before sending PHI.

User Responsibilities and Policies

Even the strongest platform cannot ensure HIPAA compliance without disciplined clinic practices. Establish and enforce the following:

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment
  • Account governance: unique accounts only; no shared logins. Implement a joiner‑mover‑leaver process and quarterly access reviews.
  • Authentication and device security: MFA, strong passphrases, endpoint encryption, patching, and mobile device management for any device used to access the portal.
  • Messaging discipline: apply the minimum necessary standard, verify recipients, avoid unnecessary attachments, and redact extraneous identifiers.
  • Operational safeguards: secure networks and Wi‑Fi, VPN where appropriate, and screen‑lock timeouts in clinical areas.
  • Policy and training: annual HIPAA training, sanctions for violations, incident reporting workflows, and documented retention/disposal rules for downloaded content.
  • Vendor management: maintain an executed BAA (when applicable), inventory subcontractors, and ensure downstream protections mirror your own requirements.

Verification of Compliance Status

To answer whether you can use the DonorNet Waitlist Messaging Portal in a HIPAA‑compliant manner, verify and document the following before go‑live:

  • Business Associate Agreement (BAA): obtain a signed BAA or confirm the governing agreement that defines HIPAA obligations for the portal. Ensure it explicitly covers messaging, attachments, and audit logging.
  • Security documentation: request a security white paper, HIPAA Security Rule control mapping, recent third‑party assessments (for example, SOC 2 Type II or equivalent), penetration test summaries, vulnerability management SLAs, and incident response procedures.
  • Technical confirmations: written attestations for Access Controls, Audit Controls, and Data Encryption (in transit and at rest), including key management and log retention periods.
  • Operational assurances: uptime commitments, disaster recovery objectives, backup and restore testing evidence, and support/escalation timelines for potential breaches.
  • Data governance: data flow diagrams, data residency, retention schedules, and procedures for data return or destruction upon contract end.

If the vendor declines to sign a BAA (or provide equivalent contractual HIPAA assurances) and cannot demonstrate adequate safeguards, you should not transmit PHI via the portal.

Risk Management and Data Protection

Perform and document a risk analysis specific to waitlist messaging. Map where ePHI is created, viewed, downloaded, or stored (including local devices, shared drives, and screenshots). For each step, record threats, likelihood, impact, and mitigating controls.

  • Strengthen endpoints: full‑disk encryption, anti‑malware, timely patching, and restricted administrative privileges.
  • Protect data flows: limit downloads, apply data loss prevention where feasible, and standardize message templates that minimize PHI exposure.
  • Monitor and respond: ingest portal audit logs into your SIEM, create alerts for unusual access or mass downloads, and maintain an incident playbook with vendor contacts.
  • Manage lifecycle: define retention for messages and attachments, secure disposal processes, and periodic review of whether stored ePHI remains necessary.

Reassess risks at least annually or after significant changes to workflows, regulations, or the platform.

Best Practices for Transplant Clinics

  • Secure the legal foundation: execute a BAA (as applicable) that clearly scopes DonorNet Waitlist Messaging Portal use.
  • Verify controls in writing: confirm Access Controls, Audit Controls, and Data Encryption standards before sending PHI.
  • Enforce least privilege and MFA for all users; review access quarterly.
  • Adopt the minimum necessary standard in every message and attachment.
  • Control endpoints: encrypt devices, manage mobile access, and restrict local PHI storage.
  • Centralize logging: retain and routinely review audit logs; investigate anomalies promptly.
  • Test preparedness: run tabletop exercises for misrouted messages, account compromise, and downtime procedures.
  • Train continuously: provide targeted, scenario‑based HIPAA training for transplant staff.

Conclusion

In practice, you can use the DonorNet Waitlist Messaging Portal in a HIPAA‑compliant manner only when a proper contractual framework (for example, a BAA where applicable) is in place, the platform’s safeguards meet HIPAA Security Rule expectations, and your clinic consistently applies strong operational controls. Verify, document, monitor, and improve—then proceed with confidence.

FAQs

What is HIPAA compliance in the context of transplant communications?

It means your clinic protects PHI and ePHI while using the portal for care coordination, satisfying the Privacy, Security, and Breach Notification Rules. Practically, you maintain a risk‑based control set, sign a BAA with any business associate, apply the minimum necessary standard, and keep auditable records of who accessed what, when, and why.

How does DonorNet protect patient health information?

You should confirm that the portal uses strong Access Controls, Multi‑Factor Authentication, comprehensive Audit Controls, and Data Encryption in transit and at rest. Request written details on key management, log retention, incident response, and disaster recovery, and pair those with your clinic’s device and user policies.

Are users of DonorNet required to sign a Business Associate Agreement?

If the platform creates, receives, maintains, or transmits ePHI on your behalf, a BAA (or equivalent contractual HIPAA terms) is generally required. Verify whether your participation or service agreement covers BAA obligations for the DonorNet Waitlist Messaging Portal; without such terms, you should not exchange PHI through the system.

How can transplant clinics verify DonorNet’s HIPAA compliance status?

Request an executed BAA, a HIPAA control mapping, third‑party assurance reports, and technical attestations for Access Controls, Audit Controls, and Data Encryption. Validate incident reporting timelines, retention schedules, and disaster recovery evidence, then document your own risk analysis and user‑side safeguards before going live.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles