LEGAL & POLICIES
HIPAA & PHI Practices
Effective date: June 8, 2026 · NexCQISolutions LLC · Atlanta, GA, USA
NexCQISolutions LLC provides credentialing, revenue cycle management and EMR services to healthcare providers. In doing so, we act as a HIPAA Business Associate. This statement describes how we handle Protected Health Information (PHI) and Electronic PHI on behalf of the providers we serve.
ON THIS PAGE
1. Our role as a Business Associate
We create, receive, maintain or transmit PHI only to perform services for covered entities under a written Business Associate Agreement (BAA), and in compliance with HIPAA and the HITECH Act.
2. Permitted uses & disclosures
We use and disclose PHI only as permitted by the applicable BAA and as required by law - for example, to perform provider credentialing, code and submit claims, operate the EMR, and respond to legally required requests. We do not use or disclose PHI for our own marketing, and we do not sell PHI.
3. Minimum necessary
We limit PHI access, use and disclosure to the minimum necessary to accomplish the intended purpose.
4. Safeguards we apply
- Encryption in transit and at rest, with customer-managed encryption keys where applicable.
- An isolated cloud environment per clinic - one practice can never reach another.
- Multi-factor authentication, least-privilege access and managed devices on a Zero-Trust model.
- Immutable audit logging retained for six years.
- A 42 CFR Part 2 firewall for substance-use and psychotherapy records.
5. 42 CFR Part 2 & sensitive records
Substance-use disorder and psychotherapy records receive heightened protection and are suppressed from billing and other workflows without the consent required by law.
6. Subcontractors
Any subcontractor that handles PHI on our behalf is bound by a written agreement imposing the same protections we are required to follow.
7. Breach notification
If a breach of unsecured PHI occurs, we notify the affected covered entity without unreasonable delay and within the timeframes required by the HITECH Act, so the provider can meet its notification obligations.
8. Individual rights
HIPAA individual rights - access, amendment, an accounting of disclosures, and requests for restrictions - are exercised through your healthcare provider. We assist the provider in fulfilling these requests as directed under the BAA.
9. No BAA, no access
A signed Business Associate Agreement is in place before any PHI flows to us. Access is never granted without it.
10. Return or destruction of PHI
On termination of a service, we return the provider's full record in a portable, standard format and securely decommission the environment, or retain and protect PHI only as permitted by the BAA and law.
11. Contact our Privacy & Security Officer
For questions about our PHI practices, contact our Privacy & Security Officer at legal@nexcqisolutions.com, NexCQISolutions LLC, Atlanta, GA, USA. Patients should also contact their healthcare provider directly.