NexPerion Solutions
Book a Call

Trust Center

Security & Healthcare Data Practices

A practical overview of the boundary between public website inquiries and client work that may involve sensitive healthcare information.

Start safely

No PHI on public forms

Share only a high-level operational challenge until the right contractual and technical safeguards are in place.

Our approach

A public website is not a secure intake channel

NexPerion does not ask visitors to submit protected health information (PHI), medical records, insurance identifiers, account credentials, or other sensitive data through public website pages, ROI calculators, or initial scheduling requests. Start with a high-level operational need instead.

Access follows the work

For client engagements, access should be limited to the people and systems that need it to perform agreed services. Access should be reviewed, removed when no longer needed, and protected with strong authentication wherever supported.

Healthcare engagements are handled contractually

When NexPerion performs services that involve PHI on behalf of a covered entity, the scope, permitted uses, safeguards, reporting expectations, and subcontractor requirements should be addressed in the applicable service agreement and business associate agreement before PHI is shared.

Use the minimum necessary information

Workflows should be designed around the minimum information needed for the assigned task. This reduces exposure while still allowing teams to schedule, verify, follow up, document, or support the operational work agreed with the client.

Security is an operating practice

NexPerion approaches security as a continuing operational responsibility: appropriate access control, vendor review, device and account hygiene, documented workflows, and a defined path for escalating suspected incidents. Specific controls are confirmed for each engagement rather than assumed from a public webpage.

No blanket compliance claim

NexPerion does not represent this public website as a HIPAA-compliant system for collecting or transmitting PHI. Healthcare compliance obligations depend on the actual service scope, data flows, contracts, systems, and roles involved in a client engagement.

Need to discuss a healthcare workflow?

Begin with a high-level description of the operational need. We can then determine the right scope, systems, and contractual path before sensitive data is involved. See the Terms of Use and Privacy Policy for the public site.