Built inside live agency operations HIPAA-aware workflows No PHI in public examples
NEXUS HELIXHome care operating system
Menu

Security and permissions module

Role-based access for every team.

Manage role-based access across 12 configurable role types, location and service-line permission scoping, AES-256 encryption at rest and TLS 1.2+ in transit, HIPAA audit log with 6+ year retention, and BAA process visibility — without unsupported certification claims.

app.nexushelix.io
Security and permissionsToday · demo · no PHI
Role types12
EncryptionAES-256
Audit retention6+ yrs
  • Role scope reviewSecurityToday
  • Audit log exportSecurityReady
  • BAA process stepSecurityTrack

Security and permissions responsibilities

The page uses safe demo labels and shows the operational states that move work forward.

Workflow responsibilities

  • Role-based access control with 12 configurable role types: owner, administrator, DON, clinical manager, field clinician, scheduler, RCM lead, billing coordinator, supervisor, caregiver, intake coordinator, location manager
  • Location and service-line permission scoping: staff see only the queues and records they are assigned to
  • AES-256 encryption at rest and TLS 1.2+ in transit for all workflow and clinical data
  • HIPAA audit log with 6+ year retention window supporting workforce compliance and access review
  • BAA process and security packet request path for Technology and compliance buyers during evaluation
  • No PHI in public screenshots, demos, or marketing examples — demo data policy enforced at product level

Role impact

  • Administrators configure role assignments, permission scopes, and location access across teams
  • Owners review access-control summary and permission change requests across service lines
  • Technology and compliance reviewers use BAA process, security packet path, and audit log posture for procurement review

Operational handoffs

Queue status is shown once in the hero product frame, then this page explains what each workflow does and where the work moves next.

Evaluator depth

This module page names the operational details an agency evaluator should expect before a demo.

Evaluator depth

What a premium security module must prove

Security buyers need concrete posture: RBAC, MFA/SSO planning, audit logs, location scoping, BAA process, encryption posture, least privilege, and incident-response language.

Specific workflow evidence

  • Role, location, service-line, and least-privilege controls
  • MFA/SSO planning and access review workflow
  • Audit-log review and security packet request process
  • BAA, encryption, and no-PHI public evidence posture

Next-module handoff

Outputs become implementation readiness, admin access review, security packet follow-up, and periodic permission audits.

Care-setting applicability

Skilled

Workflow coverage shown with demo-only public data and agency role context.

Non-skilled

Workflow coverage shown with demo-only public data and agency role context.

Private duty

Workflow coverage shown with demo-only public data and agency role context.

Multi-service

Workflow coverage shown with demo-only public data and agency role context.

Related modules

See HELIX in action

Request a demo with skilled and non-skilled care workflows.

Walk through intake, documentation, care plans, scheduling, EVV, authorizations, billing, QAPI, reporting, and mobile workflows without routing through a login wall.