Privacy Policy
Last updated: Aug 6, 2026 · Nexus Medical Network LLC · Effective for all users of the Nexus platform and website
Overview
Nexus Medical Network LLC ("Nexus," "we," "us," or "our") is a Pennsylvania limited liability company that provides administrative, management, and business support services to personal injury medical practices across New Jersey, New York, and Pennsylvania. Nexus also operates a proprietary cloud-based case coordination platform — the Nexus Platform — which supports patient coordination, scheduling, records and billing coordination, insurance claim assistance, case communication, and AI-assisted medical record summarization.
This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights available to you. It applies to information collected through our website, the Nexus Platform, intake and referral forms, and direct communications with our team — whether you are a patient, an attorney, or a healthcare provider.
Information we collect
The information we collect depends on how you interact with Nexus and the Nexus Platform:
Patients: Name, contact information, date and type of accident, injury details, insurance information, attorney information (if applicable), and medical records and billing documentation generated through treatment coordination.
Attorneys: Firm name, contact details, client referral information, case status updates, and documents submitted or requested through the attorney portal.
Providers: Practice information, authorized user credentials, scheduling data, and treatment and billing documentation submitted through the provider portal and administrative dashboard.
Website visitors: Information submitted through intake or referral forms, and limited technical data such as browser type and pages visited (see Section 10).
Protected Health Information (PHI) collected, received, maintained, or transmitted through the Nexus Platform is handled in accordance with HIPAA and the Business Associate Agreement in place with each participating provider practice.
How we use your information
We use the information we collect solely for the purposes of providing administrative services. Specifically, we use it to:
Coordinate patient care: Scheduling appointments, managing referrals, and tracking treatment status on behalf of provider practices.
Manage records and billing: Requesting, organizing, and tracking medical records and billing documentation needed throughout a case.
Support insurance claims: Providing administrative assistance with claim status tracking, documentation, and coordination between providers, attorneys, and patients.
Facilitate communication: Maintaining case communication between providers, attorneys, and patients through the Nexus Platform.
Generate AI-assisted summaries: Using AI tools to summarize medical records for administrative review (see Section 06).
Operate and improve the platform: Internal testing, validation, debugging, quality assurance, and performance monitoring — limited to the minimum necessary and in compliance with HIPAA.
Meet legal obligations:Complying with HIPAA, applicable state laws in New Jersey, New York, and Pennsylvania, and any legal process or governmental order.
Who we share information with
Nexus shares information only as necessary to provide administrative services. We do not sell personal information or PHI. Information may be shared with:
Treating providers: To facilitate scheduling, treatment coordination, and records management on behalf of the participating practice.
Attorneys: Where authorized by the patient, to provide case status updates, records, and billing documentation through the attorney portal.
Insurance carriers: Where applicable, to assist with verifying patient coverage, obtaining prior authorizations, and supporting claim-related processes.
Sub-processors: Third-party vendors who provide hosting, database, AI, communications, and other infrastructure services required to operate the Nexus Platform (see Section 09). All sub-processors are bound by confidentiality obligations and, where PHI is involved, by Business Associate Agreements.
Legal or regulatory authorities: Where required by applicable law, regulation, legal process, or governmental order. Where permitted by law, Nexus will provide notice to the affected party before disclosure.
Protected health information (HIPAA)
Nexus operates as a Business Associate under HIPAA with respect to PHI handled on behalf of participating provider practices. Our obligations are governed by the Business Associate Agreement (BAA) incorporated into the Administrative Services Agreement with each provider.
As a Business Associate, Nexus:
Uses and discloses PHI only as permitted by the BAA or as required by law.
Maintains administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic PHI in accordance with the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C).
Ensures that sub-processors who receive, maintain, or transmit PHI are bound by substantially equivalent protections under written agreements.
Provides individuals access to their PHI in a Designated Record Set as required under 45 C.F.R. § 164.524.
Incorporates amendments to PHI as required under 45 C.F.R. § 164.526.
Notifies the relevant Covered Entity of any Breach of Unsecured PHI without unreasonable delay, and no later than sixty (60) days after discovery.
Applies the minimum necessary standard when requesting, using, or disclosing PHI.
PHI is stored within Supabase and processed through the Nexus application hosted on Vercel. Access is limited to authorized users based on assigned roles and operational responsibilities.
Artificial intelligence
The Nexus Platform uses commercially hosted AI models through secure API integrations to assist with administrative functions, including medical record summarization and workflow assistance. AI functionality is intended solely to improve administrative efficiency and is not designed to diagnose patients, recommend treatment, prescribe medications, or replace the independent clinical judgment of licensed healthcare professionals.
All AI-generated content — including record summaries — is subject to user review. Nexus Platform outputs are recommendations only and do not constitute medical advice. Group practices are responsible for reviewing all Nexus Platform output for accuracy, completeness, and suitability.
With respect to PHI and AI model training:
PHI is redacted (on a best-efforts basis) before any text is transmitted to an AI model provider.
The Nexus Platform uses closed, commercially hosted AI models accessed through secure APIs. No open or open-weight models are used.
No Group data, including PHI, is used to train publicly available or generally available AI models. Models are accessed through commercial APIs whose terms prohibit training on Group inputs.
Nexus may use PHI to train or improve its own internal AI models, provided that no PHI is used to train or improve publicly available or generally available models, in accordance with the BAA.
Current AI model providers include Anthropic and OpenAI, accessed through their commercial API programs. See Section 09 for the full sub-processor list.
Data security
The Nexus Platform incorporates the following administrative, technical, and physical safeguards:
TLS 1.2+ encryption in transit
Vercel Web Application Firewall (WAF)
Daily encrypted backups with Point-in-Time Recovery (PITR)
Authenticated user access
Managed infrastructure patching
SOC 2 Type II review for key technology vendors where available
AES-256 encryption at rest
DDoS protection
Role-based access controls with Row Level Security (RLS)
Audit logging
Weekly dependency monitoring via Dependabot
No system can guarantee absolute security. In the event of a confirmed Breach of Unsecured PHI, Nexus will notify the relevant Covered Entity without unreasonable delay and no later than sixty (60) days after discovery, in accordance with HIPAA breach notification requirements.
Your rights
Depending on your role and applicable law, you may have the following rights with respect to your personal information and PHI:
Access your records
Request a copy of your PHI in a Designated Record Set, as required under 45 C.F.R. § 164.524.
Accounting of disclosures
Request a record of certain disclosures of your PHI, as provided under 45 C.F.R. § 164.528.
Request restrictions
Ask that we limit certain uses or disclosures of your PHI, subject to applicable legal requirements.
Request amendments
Ask that inaccurate or incomplete PHI be corrected, in accordance with 45 C.F.R. § 164.526.
Withdraw authorization
Revoke previously given authorization for certain uses or disclosures of your information, where applicable.
File a complaint
Raise concerns about how your information has been handled, including with the U.S. Department of Health and Human Services.
Rights requests should be directed to the contact information in Section 14. Nexus will respond within the timeframe required by applicable law and will coordinate with the relevant provider practice as needed for PHI-related requests.
Third-party sub-processors
The following sub-processors are used in connection with the Nexus Platform as of the effective date of this policy. This list is subject to change at Nexus's discretion. Provider practices may request an updated list in writing at any time.
Vercel
Application hosting and AI gateway
Amazon Web Services
Document text extraction and PHI redaction
OpenAI
AI-assisted administrative functionality
Google Maps Platform
Address geocoding and mapping
GitHub
Source code repository
DocuSign
Electronic signatures
Supabase
Database, authentication, and file storage
Anthropic
AI model provider — receives redacted text only
Resend
Transactional email delivery
PostHog
Product analytics and error monitoring
Google Workspace
Business email
Quo
Telephony and SMS
All sub-processors who access or process PHI are bound by Business Associate Agreements or equivalent contractual protections. Sub-processors are required to comply with HIPAA requirements applicable to their role in the data processing chain.
Cookies and website data
Our website may use cookies and similar technologies to understand site usage and improve performance. Limited analytics data — such as pages visited and general region inferred from IP address — may be collected through PostHog (see Section 09). This data is kept separate from medical or case records and is not used to make decisions about an individual's care or case.
You can control cookie preferences through your browser settings. Disabling cookies may affect certain website functionality but will not affect your ability to contact Nexus or submit an intake or referral form.
Data retention
We retain personal information and PHI for as long as necessary to provide administrative services, meet legal and regulatory recordkeeping requirements (including state-specific medical record retention laws in New Jersey, New York, and Pennsylvania), and resolve any disputes.
Upon termination of an Administrative Services Agreement, Nexus will, where feasible, return or destroy all PHI received from or created on behalf of the relevant provider practice, in accordance with the Business Associate Agreement. Where return or destruction is not feasible, Nexus will extend the protections of the BAA to any retained PHI and limit further use to the purposes that make return or destruction infeasible. Confidential information obligations survive termination of any agreement for a period of three (3) years.
Children's privacy
The Nexus website and platform are intended for use by adults — attorneys, providers, and adult patients. We do not knowingly collect personal information directly from children under 13 through our website. Where a minor requires medical coordination through Nexus, this is handled through a parent, legal guardian, or authorized representative, consistent with applicable law and the provider practice's consent procedures.
Provider practices are responsible for obtaining all required patient consents and authorizations — including those for minors — prior to use of the Nexus Platform in connection with a patient's care.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, platform, or legal requirements. We will post the updated policy on this page with a revised effective date. Material changes affecting how PHI is handled will be communicated to affected provider practices in accordance with HIPAA requirements and the terms of the applicable Administrative Services Agreement.
If you are a provider practice and any change to this policy affects your obligations or rights under your Administrative Services Agreement, the amendment provisions of that agreement apply.
Contact us
For questions about this Privacy Policy, to exercise a privacy right, or to report a concern, contact Nexus at: