GILNEX HIPAA COMPLIANCE NOTICE
On this page
- 1. APPLICABILITY
- 2. GILNEX'S ROLE AS BUSINESS ASSOCIATE
- 3. BUSINESS ASSOCIATE AGREEMENT (BAA)
- 4. TECHNICAL SAFEGUARDS (HIPAA Security Rule — 45 C.F.R. § 164.312)
- 5. ADMINISTRATIVE SAFEGUARDS (45 C.F.R. § 164.308)
- 6. SUBPROCESSOR HIPAA STATUS
- 7. PHI HANDLING PROCEDURES
- 8. BREACH NOTIFICATION (45 C.F.R. § 164.400–414)
- 9. CALIFORNIA CMIA COMPLIANCE
- 10. CONTACT: GILNEX PRIVACY OFFICER
Need a HIPAA Business Associate Agreement?
Contact us to request a BAA before processing any PHI.
Last Updated: June 28, 2026
1. APPLICABILITY
This Notice applies to healthcare providers, health plans, and healthcare clearinghouses ("Covered Entities" under 45 C.F.R. § 160.103) that use the GILNEX Platform and may transmit, store, or process Protected Health Information (PHI).
Using GILNEX does not by itself make your organization HIPAA-compliant. HIPAA applies when Covered Entities or their Business Associates handle PHI. If you are not a Covered Entity, or you do not process PHI through GILNEX, our Privacy Policy governs your data instead of this Notice.
2. GILNEX'S ROLE AS BUSINESS ASSOCIATE
When a Covered Entity engages GILNEX to provide services that involve PHI and has fully executed a Business Associate Agreement (BAA) with GILNEX, GILNEX acts as a "Business Associate" as defined under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the Health Information Technology for Economic and Clinical Health (HITECH) Act.
Without a fully executed BAA, GILNEX is not acting as your Business Associate and you must not transmit PHI to or through the Platform.
3. BUSINESS ASSOCIATE AGREEMENT (BAA)
A BAA is required before any PHI may be transmitted to or through the GILNEX Platform.
To request a BAA:
- Email: info@… (subject: "BAA Request — [Practice Name]")
- Processing time: Within 5 Business Days
- GILNEX will provide a standard BAA or negotiate a mutually acceptable version
No PHI should be transmitted before the BAA is fully executed.
4. TECHNICAL SAFEGUARDS (HIPAA Security Rule — 45 C.F.R. § 164.312)
| Safeguard | Implementation | |-----------|---------------| | Access Controls | Role-based access, unique user IDs, automatic logoff | | Audit Controls | Comprehensive access and activity logging | | Integrity Controls | Data validation and tamper detection | | Transmission Security | TLS 1.2+ encryption for all data in transit | | Encryption at Rest | AES-256 for stored data | | Authentication | Multi-factor authentication for admin access | | Workforce Controls | Background checks, HIPAA training, confidentiality agreements |
5. ADMINISTRATIVE SAFEGUARDS (45 C.F.R. § 164.308)
- Designated Security Officer responsible for HIPAA compliance
- Risk analysis conducted at least annually
- Workforce HIPAA training program
- Incident response and breach notification procedures
- Business Associate Agreements with all relevant subprocessors
6. SUBPROCESSOR HIPAA STATUS
GILNEX maintains HIPAA-eligible subprocessor relationships for healthcare clients:
| Subprocessor | BAA Status | Notes | |-------------|-----------|-------| | Stripe, Inc. | BAA Available | Payment processing only | | Twilio, Inc. | BAA Available | SMS/voice — healthcare-eligible plan required | | Vercel, Inc. | BAA Available | Enterprise plan required | | Google Cloud | BAA Available | Standard BAA available; Gemini AI inference for chatbot |
GILNEX will only use HIPAA-eligible configurations for clients operating under a signed BAA.
7. PHI HANDLING PROCEDURES
- PHI is processed only to the extent necessary to provide contracted services
- PHI is not used for GILNEX's internal analytics, marketing, or product development
- PHI is not disclosed to third parties except as permitted by the BAA
- PHI is returned or destroyed upon BAA termination per HIPAA requirements
8. BREACH NOTIFICATION (45 C.F.R. § 164.400–414)
In the event of a breach or suspected breach of PHI:
- GILNEX will investigate and assess the breach within 24 hours of discovery
- GILNEX will notify the affected Covered Entity within 60 calendar days of discovery
- Notification will include: description of breach, types of PHI involved, mitigation steps, and contact information
- GILNEX will cooperate fully with any required notification to individuals, HHS, and media
9. CALIFORNIA CMIA COMPLIANCE
For California-based Covered Entities, GILNEX also acknowledges obligations under the California Confidentiality of Medical Information Act (CMIA), Cal. Civ. Code § 56 et seq., which may impose additional protections beyond HIPAA.
10. CONTACT: GILNEX PRIVACY OFFICER
info@… 22647 Ventura Blvd, Suite 873, Woodland Hills, CA 91364 +1 (310) 598-2636
Questions?