HIPAA Compliance Policy

Last Updated: August 1, 2026

At Carelixy, safeguarding Protected Health Information (PHI) is our highest priority. This HIPAA Compliance Policy details our commitment to maintaining the privacy and security of patient data in accordance with the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

Data Security

End-to-end encryption for all PHI at rest and in transit, utilizing industry-standard AES-256 protocols.

Continuous Monitoring

24/7 audit logging and anomaly detection to prevent and identify unauthorized access attempts.

1. Business Associate Agreement (BAA)

As a provider of AI-driven clinical tools and telemedicine infrastructure, Carelixy operates as a Business Associate to healthcare providers (Covered Entities). We require a signed Business Associate Agreement (BAA) prior to the processing or storage of any PHI on our platform.

2. Permitted Uses and Disclosures

Carelixy will only use or disclose PHI as permitted or required by the applicable BAA or as required by law. We do not sell PHI or use it for marketing purposes without explicit patient authorization.

3. Safeguards

  • Administrative Safeguards: Regular security training for all employees, designated Privacy and Security Officers, and strict role-based access control (RBAC).
  • Physical Safeguards: Secure, SOC 2 compliant data centers provided by AWS, with restricted physical access and environmental controls.
  • Technical Safeguards: Encryption of data (in transit and at rest), secure user authentication (MFA), automated session timeouts, and comprehensive audit logs.

4. Patient Rights

We assist our Covered Entity partners in fulfilling their obligations regarding patient rights under HIPAA, including:

  • The right to access and obtain a copy of their PHI.
  • The right to request amendments to their PHI.
  • The right to receive an accounting of disclosures.
  • The right to request restrictions on certain uses and disclosures.

5. Breach Notification

In the unlikely event of a security incident resulting in the unauthorized access, use, or disclosure of unsecured PHI, Carelixy will promptly notify the affected Covered Entity in accordance with our BAA and the HIPAA Breach Notification Rule, typically within 48 hours of discovery.

Compliance Inquiries

For questions regarding our HIPAA compliance, to request a BAA, or to report a potential security concern, please contact our Privacy Officer at compliance@carelixy.com.