Built inside live agency operations HIPAA-aware workflows No PHI in public examples
NEXUS HELIXHome care operating system
Menu

Trust Center

A real Trust Center not a badge wall.

HELIX presents its HIPAA workflow safeguards, BAA process, role-based access, audit logging, tenant isolation, and data-handling posture in plain language — with an honest account of what HELIX is and is not, and no unsupported certification claims.

  • HIPAA-aware workflows
  • BAA before production PHI
  • No PHI in public examples
app.nexushelix.io
Trust & security postureToday · demo · no PHI
EncryptionAES-256
Audit retention6+ yrs
Role types12
  • HIPAA workflow safeguardsSecurityIn place
  • BAA before production PHISecurityProcess
  • Tenant isolationSecurityActive

Last reviewed June 15, 2026. This page describes product posture and is not a certification, attestation, or legal advice.

HIPAA posture

HELIX is a software workflow layer that supports an agency’s HIPAA program. The covered-entity agency remains responsible for its own compliance program.

HIPAA workflow safeguards

HELIX is built to support agency HIPAA obligations through role-based access, audit logging, minimum-necessary scoping, and access review. HELIX is a software workflow layer; the covered-entity agency remains responsible for its HIPAA program.

Business Associate Agreement (BAA)

A BAA is executed as part of onboarding before production PHI is processed. Agencies can request the BAA and security packet through implementation; the public site never exchanges PHI.

Data hosting + encryption

Production data is hosted on managed cloud infrastructure with encryption in transit (TLS 1.2+) and at rest, environment separation, and least-privilege operational access. Hosting and sub-processor detail is shared under the security packet.

Tenant + entity-level isolation

Agency data is isolated per tenant, with location, branch, and service-line permission scoping that keeps skilled, personal care, private duty, billing, and administrative work bounded to the right teams.

Audit + access review

Reviewable access and workflow-change history supports periodic access reviews, offboarding, and incident follow-up, so an agency can show who could see and change what.

No-PHI public stance

Marketing, demos, and public examples use synthetic demo data only. This is a hard product rule, not a per-page disclaimer.

Security control groups

Role-based access (RBAC)

Assign owner, administrator, clinical, scheduler, billing, and field-user permissions across configurable role types so staff only reach the workflows they are responsible for.

Tenant + entity isolation

Each agency tenant is logically separated; location, branch, and service-line scoping create entity-level boundaries so multi-site and multi-line operators keep clean operational walls.

Audit logging

Access and workflow-change history supports reviewable audit trails for permission reviews, operational follow-up, incident review, and security-packet requests.

Encryption posture

Configuration targets encryption in transit (TLS 1.2+) and at rest, with least-privilege access and key handling managed outside the public marketing surface.

Authentication controls

MFA and SSO planning, session controls, and least-privilege provisioning are scoped during implementation readiness rather than claimed as a certification.

No PHI in public examples

Every public screenshot, product frame, and example uses demo data only. No patient, staff, payer, claim, authorization, member, or agency identifiers appear on this site.

What HELIX is — and what it is not

Healthcare buyers deserve a straight answer instead of a badge wall. Here is the honest version.

Trust

What HELIX is

A HIPAA-aware clinical documentation and agency operations workflow platform for skilled home health, personal care, and private duty, with RBAC, audit logging, tenant isolation, and an executed BAA before production PHI.

Trust

What HELIX is not

HELIX does not, on this public site, claim a completed SOC 2, HITRUST, or other third-party certification. Where a certification or attestation is in progress, it is described as in progress — not as completed.

Trust

What we will share on request

A current security packet, BAA, hosting and encryption posture, access-control model, and sub-processor information, scoped to a real evaluation rather than a badge.

Trust

What stays the agency’s responsibility

Final regulatory, payer, clinical, coding, and compliance decisions remain with the agency and its qualified advisors. HELIX provides software and operational tooling, not legal, clinical, billing, or compliance advice.

How a security review works with HELIX

Security review is a real buying lane, not a footer disclaimer

Bring your security, privacy, and compliance reviewers. The path below is what to expect — no login wall before you can evaluate posture.

  • Request the BAA and current security packet through implementation
  • Review encryption, MFA/SSO, audit, RBAC, and least-privilege posture
  • Walk the location and service-line permission model for your care lines
  • Confirm hosting, environment separation, and sub-processor information
  • Verify no PHI appears in public examples, demos, screenshots, or logs

What HELIX does not claim

No unsupported compliance certification, completed third-party attestation, legal advice, payer certification, outcome guarantee, or clinical compliance guarantee is claimed on this public site. Where an attestation is in progress, it is described as in progress — never as completed.

Ask HELIX AI

NEXUS HELIX AI Guide

Use the guide to explore HELIX modules, care settings, implementation, resources, pricing, and demo readiness.

Do not enter PHI or patient information.

Does HELIX claim a healthcare certification on this site?

No. HELIX describes security controls and workflow support without unsupported certification claims. Where an attestation is in progress, it is described as in progress, never as completed.

Is there a Business Associate Agreement (BAA)?

Yes. A BAA is executed during onboarding before any production PHI is processed. The public site never exchanges PHI.

How is data protected?

Production data is hosted on managed cloud infrastructure with encryption in transit (TLS 1.2+) and at rest, tenant and entity-level isolation, role-based access, audit logging, and least-privilege operational access.

Can we get a security packet for review?

Yes. Agencies can request the BAA and current security packet through implementation, scoped to a real evaluation rather than a badge.

Is demo data used on public product visuals?

Yes. Public product frames use demo data only and visibly state that no PHI is shown.

See HELIX in action

Request a demo with skilled and non-skilled care workflows.

Walk through intake, documentation, care plans, scheduling, EVV, authorizations, billing, QAPI, reporting, and mobile workflows without routing through a login wall.