top of page

HIPAA Compliance

Our Role Under HIPAA

HealthAxis Management, LLC is a behavioral health consulting firm. We are not a health care provider, health plan, or health care clearinghouse, and we are not a Covered Entity as defined at 45 C.F.R. § 160.103. We do not provide clinical services and do not maintain designated record sets of our own.

When we perform services that involve access to protected health information (PHI) on behalf of a client that is a Covered Entity — such as billing audits, revenue cycle review, documentation review, or accreditation readiness work — we act as a Business Associate and are directly subject to the applicable provisions of the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule, as amended by the HITECH Act.

If you are a patient seeking information about your privacy rights or your health records, please contact your treating provider directly. Your provider is required to furnish you with its own Notice of Privacy Practices.

Business Associate Agreements

We execute a written Business Associate Agreement (BAA) with every client before accessing, receiving, maintaining, or transmitting PHI. Our BAAs conform to the requirements of 45 C.F.R. §§ 164.502(e) and 164.504(e) and address:

  • Permitted and required uses and disclosures of PHI

  • The prohibition on any use or disclosure not permitted by the agreement or required by law

  • Implementation of the safeguards required by the Security Rule

  • Reporting of any use or disclosure not provided for by the agreement, including breaches of unsecured PHI

  • Flow-down obligations binding any subcontractor who creates, receives, maintains, or transmits PHI on our behalf

  • Support for the Covered Entity's obligations regarding individual access, amendment, and accounting of disclosures

  • Availability of our books and records to the Secretary of Health and Human Services

  • Return or destruction of PHI upon termination of the engagement

Minimum Necessary

We request, use, and disclose only the minimum PHI necessary to perform the contracted services. Wherever the work permits, we ask clients to provide de-identified data, limited data sets, or redacted records rather than full PHI.

Safeguards We Maintain

Administrative.

Written policies and procedures; workforce confidentiality agreements; role-based access limited to personnel assigned to the engagement; HIPAA training for all workforce members; a designated Privacy and Security Officer; periodic security risk analysis; sanctions for policy violations; documented incident response and breach notification procedures.

Technical.

Unique user identification and access controls; encryption of PHI in transit and at rest consistent with HHS guidance; multi-factor authentication; audit logging; automatic logoff; secure disposal of electronic media.

Physical.

Controlled access to workspaces and devices; secure storage of any physical records; device and workstation security controls.

42 C.F.R. Part 2

Where an engagement involves substance use disorder treatment records subject to 42 C.F.R. Part 2, we additionally comply with the heightened confidentiality, redisclosure, and consent requirements of Part 2 and execute a Qualified Service Organization Agreement (QSOA) where applicable. Part 2 records are segregated and handled under access controls distinct from other PHI.

Subcontractors

We do not disclose PHI to subcontractors unless the subcontractor has executed a written agreement imposing the same restrictions and safeguards that apply to us, as required by 45 C.F.R. § 164.502(e)(1)(ii).

Breach Notification

If we discover a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and no later than [SIXTY (60)] days from discovery, or within the shorter period specified in the applicable BAA. Our notification will include the identification of each individual whose PHI was involved, the nature and extent of the PHI at issue, the identity of the recipient, whether the PHI was actually acquired or viewed, the extent to which risk has been mitigated, and the corrective actions taken.

Website Communications Are Not Secure

Our website contact forms and general email are not secure channels and must not be used to transmit PHI. Any PHI required for an engagement will be exchanged only through the encrypted method established under the applicable BAA. Information you submit through this Site is treated as business contact information and is governed by our Privacy Policy.

Retention and Return of PHI

Upon termination of an engagement, we return or securely destroy all PHI in our possession, and require the same of our subcontractors. Where return or destruction is not feasible, we extend the protections of the BAA to that information and limit further use and disclosure to the purposes that make return or destruction infeasible.

bottom of page