Privacy Policy

Last updated: Aug 6, 2026  ·  Nexus Medical Network LLC  ·  Effective for all users of the Nexus platform and website

  1. Overview

Nexus Medical Network LLC ("Nexus," "we," "us," or "our") is a Pennsylvania limited liability company that provides administrative, management, and business support services to personal injury medical practices across New Jersey, New York, and Pennsylvania. Nexus also operates a proprietary cloud-based case coordination platform — the Nexus Platform — which supports patient coordination, scheduling, records and billing coordination, insurance claim assistance, case communication, and AI-assisted medical record summarization.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights available to you. It applies to information collected through our website, the Nexus Platform, intake and referral forms, and direct communications with our team — whether you are a patient, an attorney, or a healthcare provider.

  1. Information we collect

The information we collect depends on how you interact with Nexus and the Nexus Platform:

  • Patients: Name, contact information, date and type of accident, injury details, insurance information, attorney information (if applicable), and medical records and billing documentation generated through treatment coordination.

  • Attorneys: Firm name, contact details, client referral information, case status updates, and documents submitted or requested through the attorney portal.

  • Providers: Practice information, authorized user credentials, scheduling data, and treatment and billing documentation submitted through the provider portal and administrative dashboard.

  • Website visitors: Information submitted through intake or referral forms, and limited technical data such as browser type and pages visited (see Section 10).

Protected Health Information (PHI) collected, received, maintained, or transmitted through the Nexus Platform is handled in accordance with HIPAA and the Business Associate Agreement in place with each participating provider practice.

  1. How we use your information

We use the information we collect solely for the purposes of providing administrative services. Specifically, we use it to:

  • Coordinate patient care: Scheduling appointments, managing referrals, and tracking treatment status on behalf of provider practices.

  • Manage records and billing: Requesting, organizing, and tracking medical records and billing documentation needed throughout a case.

  • Support insurance claims: Providing administrative assistance with claim status tracking, documentation, and coordination between providers, attorneys, and patients.

  • Facilitate communication: Maintaining case communication between providers, attorneys, and patients through the Nexus Platform.

  • Generate AI-assisted summaries: Using AI tools to summarize medical records for administrative review (see Section 06).

  • Operate and improve the platform: Internal testing, validation, debugging, quality assurance, and performance monitoring — limited to the minimum necessary and in compliance with HIPAA.

  • Meet legal obligations:Complying with HIPAA, applicable state laws in New Jersey, New York, and Pennsylvania, and any legal process or governmental order.

  1. Who we share information with

Nexus shares information only as necessary to provide administrative services. We do not sell personal information or PHI. Information may be shared with:

  • Treating providers: To facilitate scheduling, treatment coordination, and records management on behalf of the participating practice.

  • Attorneys: Where authorized by the patient, to provide case status updates, records, and billing documentation through the attorney portal.

  • Insurance carriers: Where applicable, to assist with verifying patient coverage, obtaining prior authorizations, and supporting claim-related processes.

  • Sub-processors: Third-party vendors who provide hosting, database, AI, communications, and other infrastructure services required to operate the Nexus Platform (see Section 09). All sub-processors are bound by confidentiality obligations and, where PHI is involved, by Business Associate Agreements.

  • Legal or regulatory authorities: Where required by applicable law, regulation, legal process, or governmental order. Where permitted by law, Nexus will provide notice to the affected party before disclosure.

  1. Protected health information (HIPAA)

Nexus operates as a Business Associate under HIPAA with respect to PHI handled on behalf of participating provider practices. Our obligations are governed by the Business Associate Agreement (BAA) incorporated into the Administrative Services Agreement with each provider.

As a Business Associate, Nexus:

  • Uses and discloses PHI only as permitted by the BAA or as required by law.

  • Maintains administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).

  • Ensures that sub-processors who receive, maintain, or transmit PHI are bound by substantially equivalent protections under written agreements.

  • Provides individuals access to their PHI in a Designated Record Set as required under 45 C.F.R. § 164.524.

  • Incorporates amendments to PHI as required under 45 C.F.R. § 164.526.

  • Notifies the relevant Covered Entity of any Breach of Unsecured PHI without unreasonable delay, and no later than sixty (60) days after discovery.

  • Applies the minimum necessary standard when requesting, using, or disclosing PHI.

PHI is stored within Supabase and processed through the Nexus application hosted on Vercel. Access is limited to authorized users based on assigned roles and operational responsibilities.

  1. Artificial intelligence

The Nexus Platform uses commercially hosted AI models through secure API integrations to assist with administrative functions, including medical record summarization and workflow assistance. AI functionality is intended solely to improve administrative efficiency and is not designed to diagnose patients, recommend treatment, prescribe medications, or replace the independent clinical judgment of licensed healthcare professionals.

All AI-generated content — including record summaries — is subject to user review. Nexus Platform outputs are recommendations only and do not constitute medical advice. Group practices are responsible for reviewing all Nexus Platform output for accuracy, completeness, and suitability.

With respect to PHI and AI model training:

  • PHI is redacted (on a best-efforts basis) before any text is transmitted to an AI model provider.

  • The Nexus Platform uses closed, commercially hosted AI models accessed through secure APIs. No open or open-weight models are used.

  • No Group data, including PHI, is used to train publicly available or generally available AI models. Models are accessed through commercial APIs whose terms prohibit training on Group inputs.

  • Nexus may use PHI to train or improve its own internal AI models, provided that no PHI is used to train or improve publicly available or generally available models, in accordance with the BAA.

Current AI model providers include Anthropic and OpenAI, accessed through their commercial API programs. See Section 09 for the full sub-processor list.

  1. Data security

The Nexus Platform incorporates the following administrative, technical, and physical safeguards:

TLS 1.2+ encryption in transit

Vercel Web Application Firewall (WAF)

Daily encrypted backups with Point-in-Time Recovery (PITR)

Authenticated user access

Managed infrastructure patching

SOC 2 Type II review for key technology vendors where available

AES-256 encryption at rest

DDoS protection

Role-based access controls with Row Level Security (RLS)

Audit logging

Weekly dependency monitoring via Dependabot

No system can guarantee absolute security. In the event of a confirmed Breach of Unsecured PHI, Nexus will notify the relevant Covered Entity without unreasonable delay and no later than sixty (60) days after discovery, in accordance with HIPAA breach notification requirements.

  1. Your rights

Depending on your role and applicable law, you may have the following rights with respect to your personal information and PHI:

Access your records

Request a copy of your PHI in a Designated Record Set, as required under 45 C.F.R. § 164.524.

Accounting of disclosures

Request a record of certain disclosures of your PHI, as provided under 45 C.F.R. § 164.528.

Request restrictions

Ask that we limit certain uses or disclosures of your PHI, subject to applicable legal requirements.

Request amendments

Ask that inaccurate or incomplete PHI be corrected, in accordance with 45 C.F.R. § 164.526.

Withdraw authorization

Revoke previously given authorization for certain uses or disclosures of your information, where applicable.

File a complaint

Raise concerns about how your information has been handled, including with the U.S. Department of Health and Human Services.

Rights requests should be directed to the contact information in Section 14. Nexus will respond within the timeframe required by applicable law and will coordinate with the relevant provider practice as needed for PHI-related requests.

  1. Third-party sub-processors

The following sub-processors are used in connection with the Nexus Platform as of the effective date of this policy. This list is subject to change at Nexus's discretion. Provider practices may request an updated list in writing at any time.

Vercel

Application hosting and AI gateway

Amazon Web Services

Document text extraction and PHI redaction

OpenAI

AI-assisted administrative functionality

Google Maps Platform

Address geocoding and mapping

GitHub

Source code repository

DocuSign

Electronic signatures

Supabase

Database, authentication, and file storage

Anthropic

AI model provider — receives redacted text only

Resend

Transactional email delivery

PostHog

Product analytics and error monitoring

Google Workspace

Business email

Quo

Telephony and SMS

All sub-processors who access or process PHI are bound by Business Associate Agreements or equivalent contractual protections. Sub-processors are required to comply with HIPAA requirements applicable to their role in the data processing chain.

  1. Cookies and website data

Our website may use cookies and similar technologies to understand site usage and improve performance. Limited analytics data — such as pages visited and general region inferred from IP address — may be collected through PostHog (see Section 09). This data is kept separate from medical or case records and is not used to make decisions about an individual's care or case.

You can control cookie preferences through your browser settings. Disabling cookies may affect certain website functionality but will not affect your ability to contact Nexus or submit an intake or referral form.

  1. Data retention

We retain personal information and PHI for as long as necessary to provide administrative services, meet legal and regulatory recordkeeping requirements (including state-specific medical record retention laws in New Jersey, New York, and Pennsylvania), and resolve any disputes.

Upon termination of an Administrative Services Agreement, Nexus will, where feasible, return or destroy all PHI received from or created on behalf of the relevant provider practice, in accordance with the Business Associate Agreement. Where return or destruction is not feasible, Nexus will extend the protections of the BAA to any retained PHI and limit further use to the purposes that make return or destruction infeasible. Confidential information obligations survive termination of any agreement for a period of three (3) years.

  1. Children's privacy

The Nexus website and platform are intended for use by adults — attorneys, providers, and adult patients. We do not knowingly collect personal information directly from children under 13 through our website. Where a minor requires medical coordination through Nexus, this is handled through a parent, legal guardian, or authorized representative, consistent with applicable law and the provider practice's consent procedures.

Provider practices are responsible for obtaining all required patient consents and authorizations — including those for minors — prior to use of the Nexus Platform in connection with a patient's care.

  1. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, platform, or legal requirements. We will post the updated policy on this page with a revised effective date. Material changes affecting how PHI is handled will be communicated to affected provider practices in accordance with HIPAA requirements and the terms of the applicable Administrative Services Agreement.

If you are a provider practice and any change to this policy affects your obligations or rights under your Administrative Services Agreement, the amendment provisions of that agreement apply.

  1. Contact us

For questions about this Privacy Policy, to exercise a privacy right, or to report a concern, contact Nexus at:

Attn:

Nexus Medical Network LLC

Phone:

610-808-2813