HIPAA Compliance

Protecting Health Information

1. Compliance Overview

Ayulex is fully compliant with the Health Insurance Portability and Accountability Act (HIPAA), including the Privacy Rule, Security Rule, and Breach Notification Rule. We operate as a secure Business Associate to our healthcare partners.

2. Core Security Safeguards

  • Administrative: Continuous workforce training, documented contingency planning, and rigorous annual risk assessments.
  • Physical: Server housing in biometrically secured, AWS-certified data centers with zero unauthorized facility access.
  • Technical: Role-based access controls (RBAC), auto-session timeouts, and mandatory Multi-Factor Authentication (MFA).

3. Immutable Audit Logging

Every interaction with Protected Health Information (PHI) is immutably logged. Our audit trails record the user identity, exact timestamp, action performed, and specific data accessed. These logs are retained securely for a minimum of 7 years.

4. Breach Notification

Ayulex maintains a 24/7 Security Operations Center. In the unlikely event of a PHI breach, we strictly adhere to HIPAA reporting protocols, notifying affected entities within the legally mandated 60-day window following discovery.