HELIX presents its HIPAA workflow safeguards, BAA process, role-based access, audit logging, tenant isolation, and data-handling posture in plain language — with an honest account of what HELIX is and is not, and no unsupported certification claims.
Last reviewed June 15, 2026. This page describes product posture and is not a certification, attestation, or legal advice.
HIPAA posture
HELIX is a software workflow layer that supports an agency’s HIPAA program. The covered-entity agency remains responsible for its own compliance program.
HIPAA workflow safeguards
HELIX is built to support agency HIPAA obligations through role-based access, audit logging, minimum-necessary scoping, and access review. HELIX is a software workflow layer; the covered-entity agency remains responsible for its HIPAA program.
Business Associate Agreement (BAA)
A BAA is executed as part of onboarding before production PHI is processed. Agencies can request the BAA and security packet through implementation; the public site never exchanges PHI.
Data hosting + encryption
Production data is hosted on managed cloud infrastructure with encryption in transit (TLS 1.2+) and at rest, environment separation, and least-privilege operational access. Hosting and sub-processor detail is shared under the security packet.
Tenant + entity-level isolation
Agency data is isolated per tenant, with location, branch, and service-line permission scoping that keeps skilled, personal care, private duty, billing, and administrative work bounded to the right teams.
Audit + access review
Reviewable access and workflow-change history supports periodic access reviews, offboarding, and incident follow-up, so an agency can show who could see and change what.
No-PHI public stance
Marketing, demos, and public examples use synthetic demo data only. This is a hard product rule, not a per-page disclaimer.
Security control groups
Role-based access (RBAC)
Assign owner, administrator, clinical, scheduler, billing, and field-user permissions across configurable role types so staff only reach the workflows they are responsible for.
Tenant + entity isolation
Each agency tenant is logically separated; location, branch, and service-line scoping create entity-level boundaries so multi-site and multi-line operators keep clean operational walls.
Audit logging
Access and workflow-change history supports reviewable audit trails for permission reviews, operational follow-up, incident review, and security-packet requests.
Encryption posture
Configuration targets encryption in transit (TLS 1.2+) and at rest, with least-privilege access and key handling managed outside the public marketing surface.
Authentication controls
MFA and SSO planning, session controls, and least-privilege provisioning are scoped during implementation readiness rather than claimed as a certification.
No PHI in public examples
Every public screenshot, product frame, and example uses demo data only. No patient, staff, payer, claim, authorization, member, or agency identifiers appear on this site.
What HELIX is — and what it is not
Healthcare buyers deserve a straight answer instead of a badge wall. Here is the honest version.
Trust
What HELIX is
A HIPAA-aware clinical documentation and agency operations workflow platform for skilled home health, personal care, and private duty, with RBAC, audit logging, tenant isolation, and an executed BAA before production PHI.
Trust
What HELIX is not
HELIX does not, on this public site, claim a completed SOC 2, HITRUST, or other third-party certification. Where a certification or attestation is in progress, it is described as in progress — not as completed.
Trust
What we will share on request
A current security packet, BAA, hosting and encryption posture, access-control model, and sub-processor information, scoped to a real evaluation rather than a badge.
Trust
What stays the agency’s responsibility
Final regulatory, payer, clinical, coding, and compliance decisions remain with the agency and its qualified advisors. HELIX provides software and operational tooling, not legal, clinical, billing, or compliance advice.
How a security review works with HELIX
Security review is a real buying lane, not a footer disclaimer
Bring your security, privacy, and compliance reviewers. The path below is what to expect — no login wall before you can evaluate posture.
Request the BAA and current security packet through implementation
Review encryption, MFA/SSO, audit, RBAC, and least-privilege posture
Walk the location and service-line permission model for your care lines
Confirm hosting, environment separation, and sub-processor information
Verify no PHI appears in public examples, demos, screenshots, or logs
What HELIX does not claim
No unsupported compliance certification, completed third-party attestation, legal advice, payer certification, outcome guarantee, or clinical compliance guarantee is claimed on this public site. Where an attestation is in progress, it is described as in progress — never as completed.
Ask HELIX AI
NEXUS HELIX AI Guide
Use the guide to explore HELIX modules, care settings, implementation, resources, pricing, and demo readiness.
Does HELIX claim a healthcare certification on this site?
No. HELIX describes security controls and workflow support without unsupported certification claims. Where an attestation is in progress, it is described as in progress, never as completed.
Is there a Business Associate Agreement (BAA)?
Yes. A BAA is executed during onboarding before any production PHI is processed. The public site never exchanges PHI.
How is data protected?
Production data is hosted on managed cloud infrastructure with encryption in transit (TLS 1.2+) and at rest, tenant and entity-level isolation, role-based access, audit logging, and least-privilege operational access.
Can we get a security packet for review?
Yes. Agencies can request the BAA and current security packet through implementation, scoped to a real evaluation rather than a badge.
Is demo data used on public product visuals?
Yes. Public product frames use demo data only and visibly state that no PHI is shown.
See HELIX in action
Request a demo with skilled and non-skilled care workflows.
Walk through intake, documentation, care plans, scheduling, EVV, authorizations, billing, QAPI, reporting, and mobile workflows without routing through a login wall.