HIPAA Policy
Effective Date: June 3, 2026
Elevion ("Company", "we", "our", or "us") builds automation, messaging, and AI systems for businesses — including medical spas, aesthetic clinics, dental practices, and wellness providers. Some of these clients are Covered Entities under the Health Insurance Portability and Accountability Act of 1996 ("HIPAA"). This policy explains how we approach protected health information ("PHI").
Our Role
Elevion is not a healthcare provider, health plan, or healthcare clearinghouse. Where our services create, receive, maintain, or transmit PHI on behalf of a Covered Entity, Elevion acts as a Business Associate and will only do so under a signed Business Associate Agreement ("BAA").
Business Associate Agreements
- No PHI is knowingly processed by Elevion before a BAA is executed.
- Subcontractors and vendors that may touch PHI (hosting, messaging, CRM, AI providers) must offer HIPAA-eligible services and execute their own BAAs.
- Where a required vendor is not HIPAA-eligible, we design the workflow so PHI never reaches that vendor.
Minimum Necessary
Systems we build are designed to collect and transmit the minimum information necessary to accomplish the intended purpose. Public-facing forms, chat widgets, and marketing automations are intentionally scoped to non-clinical contact and scheduling details, and we advise clients and prospects not to submit diagnoses, treatment details, or other clinical information through those channels.
Safeguards
Where PHI is in scope, Elevion applies:
- Administrative: role-based access, least-privilege accounts, workforce confidentiality obligations, and documented incident response.
- Technical: encryption in transit (TLS) and at rest, authentication on all administrative surfaces, row-level access controls in the database, and audit logging of privileged actions.
- Physical: reliance on cloud infrastructure providers that maintain SOC 2 / ISO 27001 certified data centers.
Breach Notification
If Elevion discovers a breach of unsecured PHI, we will notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery, and will provide the information reasonably required for the Covered Entity to meet its own notification obligations under 45 CFR §§ 164.400–414.
Client Responsibilities
- Execute a BAA with Elevion before any PHI is shared.
- Obtain any patient consent or authorization required for SMS, email, or AI-assisted communication.
- Avoid placing PHI into channels not designated for it (for example, general marketing forms, shared inboxes, or public chat).
- Maintain your own HIPAA policies, training, and risk analysis.
Information Submitted Through This Website
Forms on getelevion.com — including the Revenue Leak Audit and consultation requests — are business inquiry forms. They are not intended for PHI, and information submitted through them is handled under our Privacy Policy rather than a BAA. Please do not include patient names, health conditions, or treatment information in these submissions.
Retention and Return of PHI
Upon termination of a client engagement, Elevion will return or securely destroy all PHI in its possession where feasible, as specified in the applicable BAA. Where return or destruction is not feasible, protections are extended for as long as the information is retained.
Contact
Questions about this policy, or to request a BAA, contact elevionsupport@gmail.com or call 561-589-5637.
