Paubox blog: HIPAA compliant email made easy

Is NexHealth HIPAA compliant? (Update 2024)

Written by Caitlin Anthoney | March 18, 2021

NexHealth is a healthcare technology company that provides software solutions to medical practices, allowing them to streamline patient appointments, handle billing, and improve patient engagement. The platform offers online appointment scheduling, electronic health records (EHR) integration, patient communication tools (like automated reminders and messaging), and payment processing.

Is NexHealth HIPAA compliant? Yes, based on our research, NexHealth can be HIPAA compliant.

 

Will NexHealth sign a business associate agreement (BAA)?

Yes, NexHealth will sign a business associate agreement, which can be reviewed here.

 

What does the NexHealth BAA cover?

The NexHealth BAA covers the use and disclosure of protected health information (PHI) as per the terms outlined in the agreement. 

It specifically states, “NexHealth shall not use or disclose PHI, except for in connection with NexHealth’s performance of the services as set forth in the Underlying Agreement or as otherwise permitted under the terms of the Underlying Agreement, this BAA, or as otherwise requested or authorized by Customer; or as required or permitted by Applicable Law. NexHealth shall not use or further disclose PHI.”

Their BAA covers: 

  • Use and disclosure of PHI
  • Subcontractors
  • NexHealth management, administration, and legal responsibilities
  • Data aggregation and de-identification services
  • Delegation of responsibilities
  • Minimum necessary standard
  • Safeguards for protected health information
  • Compliance with the security rule
  • Reporting of improper use or disclosure, security incidents, and breaches
  • Individual rights
  • Access to books and records

 

What does the NexHealth BAA exclude?

NexHealth's BAA does not explicitly exclude any specific types of PHI from coverage. However, their BAA states, “NexHealth does not maintain any Designated Record Set(s) for Customer that is not duplicative of a Designated Record Set maintained by Customer.”

So, customers must ensure that they maintain accurate and comprehensive records of all protected health information (PHI) relevant to their patients. Since NexHealth does not maintain separate sets of records, customers are responsible for ensuring that their own records are complete, up-to-date, and compliant with HIPAA's requirements for privacy, security, and confidentiality.

 

Conclusion

NexHealth signs a BAA and is therefore HIPAA compliant, but customers must maintain accurate and comprehensive records of protected health information (PHI) under HIPAA regulations.

Learn more: HIPAA Compliant Email: The Definitive Guide

 

FAQS

What is a business associate agreement?

A business associate agreement (BAA) is a legally binding contract establishing a relationship between a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and its business associates. The purpose of this agreement is to ensure the proper protection of personal health information (PHI) as required by HIPAA regulations.

 

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for protecting the privacy and security of certain health information, known as protected health information (PHI).

HIPAA is designed to protect the privacy and security of individuals’ health information and to ensure that healthcare providers and insurers can securely exchange electronic health information. Violations of HIPAA can result in significant fines and penalties for covered entities.

 

Who does HIPAA apply to?

HIPAA applies to covered entities, which include healthcare providers, health plans, and healthcare clearinghouses. It also applies to business associates of these covered entities. These are entities that perform certain functions or activities on behalf of the covered entity.