Skip to main content
Compliance

HIPAA & data compliance

How NxaCare helps clinics protect health information and meet their regulatory obligations.

Last updated: May 1, 2026

Our commitment to health data protection

NxaCare is built to help clinics meet their obligations under healthcare privacy regulations, including the U.S. Health Insurance Portability and Accountability Act (HIPAA) for customers it applies to, and India's Digital Personal Data Protection (DPDP) Act, 2023.

Where HIPAA applies, NxaCare can act as a Business Associate and will enter into a Business Associate Agreement (BAA) with covered entities.

Administrative safeguards

  • Documented security policies reviewed at least annually.
  • Role-based access so staff only see the data their role requires.
  • Mandatory security training for all NxaCare employees.
  • A formal incident-response process with defined breach-notification timelines.

Technical safeguards

  • Encryption of protected health information (PHI) in transit (TLS 1.2+) and at rest (AES-256).
  • Unique user IDs, strong password policy and optional two-factor authentication.
  • Detailed audit logs of access to patient records.
  • Automatic session timeouts and least-privilege service accounts.

Physical safeguards

PHI is hosted with leading cloud providers in access-controlled, certified data centres. Physical access is restricted to authorised personnel and monitored continuously.

Business Associate Agreement (BAA)

Covered entities and their business associates can request a signed BAA before storing PHI in NxaCare. The BAA defines our responsibilities for safeguarding PHI and reporting incidents.

To request a BAA, contact our compliance team using the email below.

Breach notification

In the unlikely event of a breach affecting PHI, we will notify affected customers without undue delay and cooperate fully with their notification obligations under applicable law.

Shared responsibility

Compliance is a partnership. NxaCare provides a secure, configurable platform; clinics are responsible for managing user access, obtaining patient consents, and following their own internal policies.

Questions about this policy?

Email us at compliance@nxacare.com or reach our team via the contact page.