HIPAA Compliance Notice

Effective Date: August 14, 2026 Last Updated: August 14, 2026

Nayx is committed to upholding strict compliance with the Health Insurance Portability and Accountability Act (HIPAA), including the Privacy, Security, and Breach Notification Rules.

This Notice outlines how Nayx maintains HIPAA compliance across our technology infrastructure, software applications, and facility operations.

1. Our Role as a Technology Vendor & Business Associate

Nayx provides autonomous workforce software and clinical scheduling platforms to Covered Entities (hospitals, health systems, ambulatory surgery centers, clinics) and Business Associates.

Where Nayx creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a Covered Entity, Nayx operates as a Business Associate and enters into a formal Business Associate Agreement (BAA) with the facility before service execution.

2. On-Device AI Documentation (Zero Cloud PHI Exposure)

Nayx offers an advanced On-Device AI Clinical Documentation Engine (AI SOAP Notes) designed with a privacy-first architectural framework:

  • Local Hardware Execution: All audio recording, speech-to-text processing, and clinical note generation occur entirely on the physical hardware of the clinician's smartphone or tablet.
  • Zero Cloud Data Transit: No ambient clinical audio, voice snippets, transcripts, or patient identifiers generated during local AI charting are transmitted over the internet or saved to cloud servers.
  • No Third-Party AI Data Training: Nayx does not send patient encounters or audio data to external third-party cloud LLM providers. Patient data is never used to train public machine-learning models.

3. Administrative, Technical, and Physical Safeguards

Nayx enforces rigorous security controls in accordance with the HIPAA Security Rule:

A. Technical Safeguards

  • End-to-End Encryption: Encryption of data in transit via TLS 1.3 and data at rest using AES-256 bit encryption protocols.
  • Role-Based Access Control (RBAC): Strict access controls ensuring users access only the minimum necessary information required for shift fulfillment and administrative logging.
  • Audit Controls: Centralized logging of all platform system access, shift posting actions, credential validations, and administrative approvals.

B. Administrative Safeguards

  • SOC 2 Type II (Audit in Progress) Audited Infrastructure: Continuous auditing of technical infrastructure security and operational controls.
  • Employee Workforce Training: Mandatory HIPAA compliance training and security protocols for all Nayx personnel with system support roles.
  • Incident Response & Breach Notification: Formal policies for investigating, mitigating, and reporting suspected security incidents or unauthorized PHI disclosures in accordance with statutory guidelines.

C. Physical Safeguards

  • Hosted exclusively on enterprise-grade, high-availability cloud data center infrastructure equipped with 24/7 physical security access controls, biometric authorization, and environmental safeguards.

4. Business Associate Agreements (BAA)

Healthcare Facilities partnering with Nayx can execute a standardized Business Associate Agreement (BAA) covering platform integration, workforce analytics, and credential routing.

To request or execute a BAA with Nayx, please contact our compliance desk at info@nayx.ai.

5. Contacting the Privacy & Compliance Officer

If you have questions regarding our HIPAA policies, wish to report a compliance concern, or need to execute a BAA:

Email: info@nayx.ai

Ask AI