top of page

HIPAA & Security Statement

 

1. Our Commitment

Aidion, LLC, dba: Aidion Health ("we," "us," "our") knows that healthcare organizations trust us with sensitive information, including Protected Health Information (PHI). We are committed to protecting the confidentiality, integrity and availability of that information. We keep administrative, physical and technical safeguards in place that meet the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the HITECH Act, and their implementing regulations.

 

2. Our Role Under HIPAA

When we provide services to healthcare providers, health plans or other covered entities, we act as a Business Associate under HIPAA. We sign a Business Associate Agreement (BAA) with each covered entity customer before we receive, create, maintain or transmit PHI for them. We use and disclose PHI only as the BAA permits and as the law requires.

 

3. Administrative Safeguards

  • Security & Privacy Officer: We have appointed a Security and Privacy Officer who is responsible for our HIPAA compliance program.

  • Risk assessments: We run regular risk assessments to find and address potential threats to PHI.

  • Workforce training: Everyone on our workforce who may access PHI receives HIPAA and security training when hired and at least once a year after that.

  • Policies & procedures: We keep written policies covering access, incident response, contingency planning and sanctions for violations.

  • Minimum necessary access: Access to PHI is limited to the minimum needed to do the job.

​​

4. Technical Safeguards

We apply strict technical controls built on industry best practices and recognized frameworks, including NIST SP 800-53 and the HITRUST CSF.

  • Encryption everywhere: PHI is encrypted in transit with TLS 1.2 or higher, using strong cipher suites and enforced HTTPS (HSTS). It is encrypted at rest with AES-256. Keys are managed in a dedicated key management service backed by FIPS 140-validated hardware security modules (HSMs), with strict access policies and regular key rotation.

  • Zero-trust access control: Access follows the principle of least privilege. Users have unique IDs and role-based permissions, and all administrative and production access requires multi-factor authentication. Privileged access is granted just in time, reviewed regularly, and revoked promptly when no longer needed.

  • Network security: Production systems run in isolated, private virtual networks with segmentation, restrictive security groups, web application firewalls (WAF) and managed DDoS protection. Nothing is exposed to the public internet unless it has to be.

  • Continuous monitoring & threat detection: Security events are logged centrally in tamper-resistant audit logs and watched continuously by automated threat detection and alerting. Unusual activity is investigated and handled under our documented incident response plan.

  • Vulnerability management: We run automated vulnerability scanning, patch promptly on defined timelines, secure our dependencies and software supply chain, and have independent third parties do periodic penetration testing.

  • Secure development lifecycle: Code goes through peer review and automated security testing before release. Infrastructure is defined as code so every environment is consistent and auditable, and production data is never used in development or test environments.

  • Integrity & availability: Checksums, versioning and immutable backups protect data against unauthorized changes or destruction. Automatic session timeouts protect idle sessions.

 

5. Physical Safeguards

Our infrastructure is hosted on [Amazon Web Services (AWS)], whose data centers are among the most secure in the world. AWS undergoes independent third-party audits against standards including SOC 1, SOC 2 and SOC 3, ISO/IEC 27001, 27017 and 27018, FedRAMP, PCI DSS Level 1 and HITRUST CSF, and offers HIPAA-eligible services covered under a Business Associate Addendum.

​

These data centers provide:

 

  • Restricted perimeter and building access: professional security staff on site around the clock, video surveillance, intrusion detection, and multi-factor authentication (including biometrics) at controlled entry points.

  • Strictly limited access: only pre-approved personnel with a legitimate business need get in, access is time-limited, and every entry is logged and audited.

  • Environmental protections: fire detection and suppression, climate and temperature control, and redundant power with uninterruptible power supplies (UPS) and backup generators.

  • Geographic redundancy: multiple physically separate Availability Zones, which lets us build highly available, fault-tolerant systems with resilient backups.

  • Secure media destruction: storage devices are decommissioned and destroyed following NIST SP 800-88 media sanitization guidelines.

​​

Inside our own organization, workstations and devices that can access PHI have full-disk encryption, endpoint protection and centralized management, and can be wiped remotely.

​​

6. Third-Party Vendors

Any subcontractor or service provider that may handle PHI for us must sign a BAA with us first. That BAA requires them to protect PHI to the same standard we do.

​​

7. Data Backup & Business Continuity

We keep secure, encrypted backups and have documented disaster recovery and business continuity plans to keep data available.

​

8. Breach Notification

If a breach of unsecured PHI happens, we will notify affected customers without unreasonable delay, as HIPAA, the HITECH Act and our BAAs require.

​

9. Data Retention & Disposal

We keep PHI only as long as our agreements or the law require. When it's no longer needed, we dispose of it securely, following HHS guidance.

​

10. Continuous Improvement

Security is an ongoing process. We review and update our safeguards regularly to keep up with new threats, changes in technology and changes in regulations.

​

11. Contact Us

For questions about our HIPAA compliance or security practices, or to request a Business Associate Agreement, please contact:

Email: legal@aidion.ai

Phone: 352-752-7500
last updated 01/14/2026

bottom of page