Security & Compliance

Behavioral-health data requires disciplined protection.

Axis handles revenue-cycle information under written client agreements, plus a Business Associate Agreement whenever the work requires access to protected health information. The controls are scoped to each engagement.

In short

Controls
around the
data.

PHI · ACCESS · TRANSFER
Defined by agreement, applied per engagement

First

BAA before any PHI is exchanged

Access

Handled only by the two accountable principals

Boundary

PHI never through the public site

Controls

How Axis protects client and patient data.

Client work runs in a HIPAA-eligible Microsoft 365 environment under a Business Associate Agreement with Microsoft — encrypted at rest and in transit, with multifactor authentication required. PHI is handled only by the two accountable Axis principals — not an offshore team or rotating contractors — and returned or destroyed at the end of each engagement. Controls are established during contracting and onboarding around the systems, work, and minimum information each engagement requires.

01

Business Associate Agreements

A written BAA defines permitted PHI use, security duties, incident and subcontractor obligations, and return-or-destruction terms before data is exchanged.

02

Named user accounts

Individual named accounts identify every person who accesses systems used for client work.

03

Multifactor authentication

Multifactor authentication is required on accounts with access to systems that handle PHI.

04

Role-based access

Permissions are limited to the information and actions each user is authorized to perform.

05

Approved secure transfer

PHI moves only through approved secure transfer methods — never the public website or review form.

06

Encryption verification

Encryption is verified for each system used to store or transmit PHI.

07

Access & activity records

Systems retain access and activity records appropriate to the work performed, where supported.

08

Vendor & subcontractor review

Vendors that handle PHI are reviewed for their role and placed under required contractual safeguards before use.

09

Incident & breach response

A documented process governs identification, response, and required notification for security incidents.

10

Workforce training

Workforce members are trained on PHI handling and the minimum-necessary standard.

11

Risk analysis & remediation

Security risk analysis is performed periodically, with identified issues tracked to remediation.

12

Data retention & destruction

Retention periods and secure destruction of PHI are defined by agreement.

Important. This page summarizes Axis practices and is not a certification, legal opinion, or substitute for the executed service agreement and Business Associate Agreement. Specific systems, controls, and responsibilities are confirmed during contracting and onboarding.

Vetting us

What compliance teams ask before onboarding.

Do you sign a Business Associate Agreement before we send anything?

Yes, and it comes first: the BAA is in place before any PHI is exchanged. It spells out permitted PHI use, security duties, incident and subcontractor obligations, and return-or-destruction terms. That sits alongside the written client agreement covering the engagement itself.

Who at Axis actually sees our patient data?

Two people. PHI is handled only by the two accountable Axis principals, not an offshore team or rotating contractors. Everyone accessing systems used for client work does so under an individual named account, with permissions limited to the information and actions that person is authorized to perform.

Where does our data live once we hand it over, and is it encrypted?

Client work runs in a HIPAA-eligible Microsoft 365 environment under a Business Associate Agreement with Microsoft, encrypted at rest and in transit. Multifactor authentication is required on accounts with access to systems that handle PHI. Encryption is also verified for each system used to store or transmit it.

How do we get claim files and PHI to you securely?

Through approved secure transfer methods established during contracting and onboarding — never through the public website or the review form. Each engagement is scoped to the systems, work, and minimum information it actually requires.

What happens to our data when the engagement ends?

It gets returned or destroyed. That happens at the end of each engagement, with retention periods and secure destruction defined by agreement. The BAA itself includes return-or-destruction terms before any data is exchanged.

What is your process if there is a security incident or breach?

A documented process governs identification, response, and required notification for security incidents. Incident obligations are also written into the BAA before data changes hands. On the preventive side, security risk analysis is performed periodically and identified issues are tracked to remediation.

Ready to talk security before onboarding?

Get in touch.

We'll share the security and compliance detail your team needs to move forward — under the appropriate agreement.

Last updated: July 5, 2026