Business Associate Agreements
A written BAA defines permitted PHI use, security duties, incident and subcontractor obligations, and return-or-destruction terms before data is exchanged.
Security & Compliance
Axis handles revenue-cycle information under written client agreements, plus a Business Associate Agreement whenever the work requires access to protected health information. The controls are scoped to each engagement.
In short
Controls
around the
data.
PHI · ACCESS · TRANSFER
Defined by agreement, applied per engagement
First
BAA before any PHI is exchanged
Access
Handled only by the two accountable principals
Boundary
PHI never through the public site
Controls
Client work runs in a HIPAA-eligible Microsoft 365 environment under a Business Associate Agreement with Microsoft — encrypted at rest and in transit, with multifactor authentication required. PHI is handled only by the two accountable Axis principals — not an offshore team or rotating contractors — and returned or destroyed at the end of each engagement. Controls are established during contracting and onboarding around the systems, work, and minimum information each engagement requires.
A written BAA defines permitted PHI use, security duties, incident and subcontractor obligations, and return-or-destruction terms before data is exchanged.
Individual named accounts identify every person who accesses systems used for client work.
Multifactor authentication is required on accounts with access to systems that handle PHI.
Permissions are limited to the information and actions each user is authorized to perform.
PHI moves only through approved secure transfer methods — never the public website or review form.
Encryption is verified for each system used to store or transmit PHI.
Systems retain access and activity records appropriate to the work performed, where supported.
Vendors that handle PHI are reviewed for their role and placed under required contractual safeguards before use.
A documented process governs identification, response, and required notification for security incidents.
Workforce members are trained on PHI handling and the minimum-necessary standard.
Security risk analysis is performed periodically, with identified issues tracked to remediation.
Retention periods and secure destruction of PHI are defined by agreement.
Important. This page summarizes Axis practices and is not a certification, legal opinion, or substitute for the executed service agreement and Business Associate Agreement. Specific systems, controls, and responsibilities are confirmed during contracting and onboarding.
Vetting us
Yes, and it comes first: the BAA is in place before any PHI is exchanged. It spells out permitted PHI use, security duties, incident and subcontractor obligations, and return-or-destruction terms. That sits alongside the written client agreement covering the engagement itself.
Two people. PHI is handled only by the two accountable Axis principals, not an offshore team or rotating contractors. Everyone accessing systems used for client work does so under an individual named account, with permissions limited to the information and actions that person is authorized to perform.
Client work runs in a HIPAA-eligible Microsoft 365 environment under a Business Associate Agreement with Microsoft, encrypted at rest and in transit. Multifactor authentication is required on accounts with access to systems that handle PHI. Encryption is also verified for each system used to store or transmit it.
Through approved secure transfer methods established during contracting and onboarding — never through the public website or the review form. Each engagement is scoped to the systems, work, and minimum information it actually requires.
It gets returned or destroyed. That happens at the end of each engagement, with retention periods and secure destruction defined by agreement. The BAA itself includes return-or-destruction terms before any data is exchanged.
A documented process governs identification, response, and required notification for security incidents. Incident obligations are also written into the BAA before data changes hands. On the preventive side, security risk analysis is performed periodically and identified issues are tracked to remediation.
Ready to talk security before onboarding?
We'll share the security and compliance detail your team needs to move forward — under the appropriate agreement.
Last updated: July 5, 2026