Legal

HIPAA Compliance

NuGenera Health performs revenue cycle management services that involve protected health information (PHI). As a business associate to the practices we serve, we operate under the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and applicable state privacy laws.

Our role as a business associate

When we handle PHI on behalf of a covered entity, we do so under a signed Business Associate Agreement (BAA) that defines permitted uses, safeguards, and breach-notification obligations. We use PHI only to perform the contracted services and as otherwise permitted by the BAA.

Administrative safeguards

We maintain written policies and procedures, assign responsibility for security oversight, conduct workforce training, and apply role-based access so team members can reach only the information required for their work.

Technical safeguards

We use access controls, encryption of data in transit, secure document exchange, and audit logging designed to detect and record access to systems that contain PHI.

Physical safeguards

We restrict physical and logical access to systems and workstations used to process PHI and follow procedures for secure disposal of information that is no longer needed.

Breach notification

In the event of a suspected breach of unsecured PHI, we follow the notification timelines and processes set out in our Business Associate Agreements and applicable law.

Contact

Questions about our HIPAA practices can be directed to hello@nugenerahealth.com or (855) 455-2873.

Last updated: March 15, 2026.