Business Associate Privacy Practices
Effective: July 28, 2026 · Version 1.0
Who We Are and Our Role
Axeum Technologies, Inc. ("Axeum") provides governed provider intelligence through the axeumCARE product family, its healthcare sub-vertical. This includes axeumFLOW (the digital SaaS platform operated at care.axeumai.com) and its companion products axeumAURA, axeumCOMPANION, and axeumSENSE. Where any axeumCARE product processes health information on behalf of a healthcare practice or organization, Axeum acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. This statement applies to all axeumCARE products.
The healthcare practice is the Covered Entity. The practice is responsible for the care of its patients and for issuing its own Notice of Privacy Practices to those patients. Axeum does not have a direct relationship with patients and does not issue notices to them. This statement explains how Axeum handles the health information it receives from a practice in order to support that practice's operations.
What Health Information We Process
Axeum receives and processes Protected Health Information (PHI) that a practice shares with it to deliver services, including: appointment and scheduling data; clinical documentation and encounter notes; diagnosis and procedure codes; insurance and billing information; remittance and payment data; and remote patient monitoring data where applicable.
Axeum applies the minimum-necessary standard — it accesses and uses only the PHI required to perform the specific service the practice has engaged it to deliver.
How We Use and Disclose Health Information
Axeum uses PHI only as permitted under its Business Associate Agreement with the practice and applicable law:
- Treatment, Payment, and Healthcare Operations. Axeum processes PHI to support the practice's clinical workflows, revenue cycle management, compliance auditing, and quality reporting.
- AI-Assisted Analysis. When PHI is submitted to AI processing (including large language model analysis), Axeum de-identifies the information before transmission to third-party AI providers, consistent with 45 C.F.R. §164.514. Identifiable PHI is never transmitted to AI providers in identifiable form.
- Subcontractors. Axeum may disclose PHI to sub-processors operating under Business Associate Agreements with Axeum, including: Amazon Web Services (Transcribe Medical, infrastructure), Microsoft (authentication services), Vercel (platform hosting), and Neon (database infrastructure). All such sub-processors are bound by HIPAA-compliant data processing agreements.
- Required by Law. Axeum will disclose PHI as required by law, including in response to valid court orders, subpoenas, or regulatory requests.
- Breach Notification. Axeum will notify the practice of any breach of unsecured PHI as required by the HITECH Act Breach Notification Rule (45 C.F.R. Part 164, Subpart D), so the practice can meet its own patient-notification obligations.
What We Will Not Do
Axeum will not: sell PHI; use it for marketing purposes; use it to train AI models without explicit authorization; or disclose it for any purpose not permitted under its Business Associate Agreement with the practice.
Patient Rights
Because Axeum is a Business Associate and has no direct relationship with patients, all patient rights under HIPAA — access to records, amendment, an accounting of disclosures, and restriction requests — are exercised through the patient's healthcare practice, the Covered Entity. Axeum supports the practice in fulfilling those requests as required under the Business Associate Agreement.
Security
Axeum implements administrative, physical, and technical safeguards consistent with the HIPAA Security Rule (45 C.F.R. §§164.308–164.318), including: encrypted data transmission and storage; tenant-scoped data isolation; append-only cryptographically signed audit records; role-based access controls; and automatic session timeout.
Contact
For questions about this statement or Axeum's privacy practices:
Axeum Technologies, Inc.
Privacy Officer: Stephen Piscitelli
privacy@axeumai.com
Changes to This Statement
Axeum reserves the right to change this statement. The current version will always be available at axeumai.com/hipaa-notice.html.