HIPAA Notice
Last updated: June 2026. This notice describes how Aegis BioCryption (“Aegis”) handles Protected Health Information (“PHI”) in its role as a Business Associate under the Health Insurance Portability and Accountability Act of 1996, the HITECH Act, and their implementing regulations (collectively, “HIPAA”). It is informational; the binding terms are set out in the executed Business Associate Agreement (“BAA”).
1. Our Role as a Business Associate
Aegis provides a secure transfer layer to Covered Entities and their Business Associates. When we create, receive, maintain, or transmit PHI on your behalf, we act as a Business Associate. We enter into a BAA with each customer before any PHI is processed through the Service. We use and disclose PHI only as permitted by the BAA, as required to provide the Service, or as required by law, and we do not use or disclose PHI for our own marketing, advertising, or analytics.
2. Safeguards (Security Rule)
We implement administrative, physical, and technical safeguards reasonable and appropriate to protect the confidentiality, integrity, and availability of electronic PHI, including: end-to-end encryption in transit (TLS 1.2+) and at rest (AES-256) under a per-study key destroyed on expiry; least-privilege, role-based, and time-boxed access; single-purpose, short-lived signed URLs so the payload is never parked in systems that do not need it; and a tamper-evident, hash-chained audit trail whose root hash is periodically anchored to a public timestamp for independent verification.
3. Minimum Necessary
The Service is designed around the minimum-necessary principle: only the specific study that has been requested and authorized is released, and access is limited to a single time-boxed window with download and export blocked. The imaging payload is never decrypted in our application layer — it moves as ciphertext between the endpoint and sealed storage. The patient identifiers needed to route and label a study are held encrypted at rest (per-field envelope encryption), exposed only as the minimum necessary to the authorized parties, and decrypted only transiently to authorize and display a transfer. Operational and billing systems are architected so that PHI never enters them.
4. Breach Notification
Consistent with the HITECH Act and the Breach Notification Rule, we maintain incident-response procedures and will, without unreasonable delay and as specified in the BAA, notify the affected customer following discovery of a breach of unsecured PHI, providing the information necessary for the customer to meet its notification obligations.
5. Subcontractors
Where we engage subcontractors that create, receive, maintain, or transmit PHI on our behalf, we require them to agree in writing to restrictions and conditions at least as protective as those that apply to us under the BAA, as required by HIPAA.
6. Individual Rights
HIPAA grants individuals rights regarding their PHI (such as access and amendment). Because Aegis is a Business Associate and does not have the direct relationship with the individual, such requests are directed to and fulfilled by the Covered Entity. We support Covered Entities in meeting these obligations as set out in the BAA.
7. Data Location and Destruction
PHI is processed and stored within access-controlled cloud infrastructure in the region agreed with the customer. Released studies carry an auto-destruct window; at the end of the window, or on demand, the payload is irreversibly destroyed and the disposal is recorded in the anchored audit trail. Retention and return or destruction of PHI on termination are governed by the BAA.
8. Requesting the BAA
Covered Entities and Business Associates can obtain our Business Associate Agreement and a controls summary for security review before any PHI is exchanged. Request the BAA or email support@aegisbiocryption.com.
This notice is provided for transparency and does not constitute legal advice or modify any executed agreement. The Business Associate Agreement controls the parties’ obligations with respect to PHI.