HIPAA Notice of Privacy Practices

Last updated: Aug 6, 2026  ·  Nexus Medical Network LLC  ·  This notice is required by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 C.F.R. Parts 160 and 164).

  1. Who we are

Nexus Medical Network LLC ("Nexus," "we," "us," or "our") is a Pennsylvania limited liability company that provides administrative, management, and business support services to personal injury medical practices. Nexus operates as a Business Associate under HIPAA — meaning we receive, maintain, transmit, or create Protected Health Information (PHI) on behalf of participating healthcare provider practices (Covered Entities) in order to perform administrative services.

Nexus is not itself a Covered Entity under HIPAA. We do not provide medical care, diagnose or treat patients, or prescribe medications. All clinical and medical decisions remain with licensed healthcare professionals at the provider practices we support.

  1. Our legal duties

Under HIPAA and the Business Associate Agreements in place with each participating provider practice, Nexus is required to:

  • Maintain the privacy of your PHI and protect it from uses and disclosures not permitted by applicable law or the relevant Business Associate Agreement.

  • Provide you with notice of our privacy practices regarding your PHI, as required by 45 C.F.R. § 164.520.

  • Maintain administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).

  • Notify the relevant Covered Entity of any Breach of Unsecured PHI without unreasonable delay and no later than sixty (60) days after discovery.

  • Abide by the terms of this notice as currently in effect.

  1. How we use and disclose your PHI

As a Business Associate, Nexus uses and discloses PHI only as permitted by the Business Associate Agreement with the relevant provider practice, as required by law, or as described in this notice. The following are the primary ways in which Nexus uses or discloses PHI:

Patient scheduling

Coordinating referrals, scheduling appointments, and tracking treatment status on behalf of provider practices.

Insurance claim assistance

Providing administrative support for insurance claims, including documentation coordination between providers, attorneys, and patients.

AI-assisted record summaries

Generating administrative summaries of medical records using AI tools. PHI is redacted on a best-efforts basis before transmission to any external AI model provider.

Attorney coordination

Sharing case status and documentation with authorized attorneys where you have authorized your provider to share your information in connection with your legal case.

Records and billing coordination

Requesting, organizing, and tracking medical records and billing documentation across treating providers.

Case communication

Facilitating communication between providers, attorneys, and patients through the Nexus Platform in connection with a specific case.

Platform operations

Internal testing, validation, debugging, and quality assurance — limited to the minimum necessary and in compliance with HIPAA.

Legal compliance

Disclosures required by applicable law, court order, subpoena, or regulatory requirement. Where permitted, we will seek to provide notice before disclosure.

Nexus applies the minimum necessary standard when requesting, using, or disclosing PHI — meaning we access only the PHI needed to perform the specific administrative function.

We do not sell your PHI and do not use it for marketing purposes. PHI is never used to train publicly available or generally available AI models.

  1. Uses requiring your authorization

Nexus will not use or disclose your PHI for purposes beyond those described in this notice without your written authorization, except as required by law. Uses that require your separate written authorization include:

  • Marketing communications that involve the use of your PHI.

  • Sale of your PHI to any third party.

  • Most uses and disclosures of psychotherapy notes.

  • Any other use or disclosure not permitted by HIPAA without authorization.

You may revoke any written authorization you have provided at any time, in writing, directed to your treating provider or to Nexus (see Section 09). Revocation does not affect uses or disclosures that occurred before your revocation.

  1. Your rights regarding your PHI

You have the following rights with respect to your PHI that Nexus holds or has access to in its role as a Business Associate. To exercise any of these rights, contact us as described in Section 09. Nexus will coordinate with the relevant provider practice as needed.

Right to access your PHI (45 C.F.R. § 164.524)

You have the right to inspect and receive a copy of your PHI that Nexus holds in a Designated Record Set. We will respond to your request within thirty (30) days, with one possible thirty (30) day extension. We may charge a reasonable cost-based fee for copies.

Right to amend your PHI (45 C.F.R. § 164.526)

If you believe PHI we hold about you is inaccurate or incomplete, you may request an amendment. We will act on your request within sixty (60) days. We may deny the request in certain circumstances, such as when the information was not created by Nexus or is accurate as recorded.

Right to an accounting of disclosures (45 C.F.R. § 164.528)

You may request a list of certain disclosures of your PHI made by Nexus in the six (6) years prior to your request. This right does not apply to disclosures for treatment, payment, or healthcare operations, or disclosures you authorized.

Right to request restrictions (45 C.F.R. § 164.522)

You may request that Nexus limit how it uses or discloses your PHI. Nexus is not required to agree to all restrictions, but if we do agree, we are bound by that agreement except in emergencies or as required by law.

Right to confidential communications

You may request that Nexus communicate with you in a specific way or at a specific location. We will accommodate reasonable requests.

Right to a paper copy of this notice

You may request a paper copy of this Notice of Privacy Practices at any time, even if you received it electronically. Contact us at the information in Section 09.

  1. How we protect your PHI

Nexus maintains administrative, physical, and technical safeguards to protect PHI against unauthorized access, use, or disclosure, in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C). Our key safeguards include:

  • Encryption: TLS 1.2+ encryption for all data in transit; AES-256 encryption for data at rest.

  • Access controls: Role-based access controls with Row Level Security ensure that authorized users access only the PHI relevant to their role and assigned cases.

  • Audit logging: All access to and activity on PHI within the Nexus Platform is logged with actor, timestamp, and action.

  • Backup and recovery: Daily encrypted backups with Point-in-Time Recovery to protect against data loss.

  • Network security: Web Application Firewall and DDoS protection on all platform infrastructure.

  • Sub-processor oversight: All third-party vendors who access PHI are bound by Business Associate Agreements and required to maintain equivalent protections.

  • AI PHI redaction: PHI is redacted on a best-efforts basis before any text is transmitted to an external AI model provider. Only closed, commercially hosted models accessed through secure APIs are used.

  1. Breach notification

In the event of a Breach of Unsecured PHI, Nexus will notify the relevant Covered Entity (your provider practice) without unreasonable delay and no later than sixty (60) days after discovery of the breach, in accordance with 45 C.F.R. § 164.410.

Notification will include, to the extent possible:

  • A description of the breach, including the date it occurred and the date it was discovered.

  • A description of the types of PHI involved.

  • Steps individuals should take to protect themselves from potential harm.

  • A description of what Nexus is doing to investigate, mitigate harm, and prevent future breaches.

Your provider practice is responsible for notifying you of a breach affecting your PHI, consistent with their own HIPAA obligations as a Covered Entity. Nexus cooperates fully with affected provider practices in breach response and notification.

  1. Changes to this notice

Nexus reserves the right to change the terms of this Notice of Privacy Practices at any time, consistent with applicable law. Any revised notice will apply to PHI already held by Nexus as well as PHI received or created in the future. When we make a material change, we will post the revised notice on this page with an updated effective date and notify affected provider practices accordingly.

You may obtain the current version of this notice at any time by visiting this page or by contacting us as described in Section 09.

  1. How to exercise your rights

For questions about these To exercise any of your rights described in this notice, or to request a paper copy of this notice, contact Nexus in writing at: of Service or to report a concern, contact Nexus at:

Attn:

Nexus Medical Network LLC

Phone:

610-808-2813

We will respond to all rights requests within the timeframes required by HIPAA. We may need to verify your identity before processing a request. In most cases, we will coordinate with your treating provider practice to fulfill your request, as the Covered Entity responsible for your Designated Record Set.

You will not be penalized or denied services for exercising your HIPAA rights.

  1. How to file a complaint

If you believe your privacy rights have been violated, you may file a complaint with Nexus or directly with the U.S. Department of Health and Human Services, Office for Civil Rights. You will not be retaliated against for filing a complaint.

To file a complaint with Nexus, contact us as described in Section 09 and describe your concern in writing. We will acknowledge receipt and investigate all complaints promptly.

To file a complaint with the federal government:

U.S. Department of Health and Human Services — Office for Civil Rights

Phone:

1-800-368-1019 (toll-free)  ·  1-800-537-7697 (TDD)

Mail:

U.S. Department of Health and Human Services, 200 Independence Avenue, S.W., Washington, D.C. 20201