Health Insurance Portability and Accountability Act (HIPAA)
LawVu enables you to operate your legal workspace in accordance with your HIPAA compliance obligations. HIPAA is a federal regulation developed by the United States Department of Health and Human Services. It is designed to protect the privacy and security of people's protected health information (PHI or ePHI).
HIPAA applies to covered entities and business associates that create, receive, maintain, access, or send PHI or ePHI. It is your responsibility to ensure your compliance with HIPAA and determine whether you must enter into a Business Associate Agreement (BAA) with LawVu.
The BAA outlines the terms and conditions for safeguarding PHI or ePHI. Under HIPAA, LawVu is considered a business associate. Therefore, a BAA must be signed before you upload PHI or ePHI to the LawVu services. To request a BAA, your Organization Admin should email legal@lawvu.com.
The sections below explain how to configure LawVu settings to ensure your workspace is used in a HIPAA-compliant manner.
In this article:
Signing in to LawVu – Two-factor Authentication
When two-factor authentication is enabled, users will see a modal window during sign-in that requires them to enter a verification code sent via email.
Note: Organization administrators can disable this feature. Click here to learn more.
Disable sending User Data via email from LawVu
LawVu will apply settings to restrict the sharing of information with third parties via the email functionality in the LawVu platform.
External communication tools are disabled. This means the 'Send by Email' option in the Files tab of a matter is unavailable. To easily share documents within a matter, we recommend using LawVu’s Outlook add-in. You can find more details about LawVu's add-in for Outlook in this article.
The email address of a matter, contract, or associated conversation is not available to be shared.
Users can freely share documents via email with other LawVu users in their organization.
Disable sending User Data in email notifications
The matter or contract name, as well as the content of conversations or assignments, will be removed from all email notifications sent from the LawVu platform.
To see the contents of the email notification, a user must log in to their LawVu account.
Setting the Inactivity Period
To enhance security, Organization Administrators can configure LawVu to automatically log out inactive user accounts after a set duration.
By default, LawVu automatically logs out users after 10 minutes of inactivity, calculated from their last click. Upon automatic logout, users must log in again and be reauthenticated. They will then be redirected to the exact page they were on before the inactivity timeout.
Organization Administrators can adjust this inactivity timeout from 5 to 30 minutes to align with their organization's workstation security policies.
Please note: The inactivity timeout feature cannot be disabled.
Your security settings in LawVu can be accessed from Organization Settings > General Settings > Security.


