HIPAA and Your Practice Data
Last updated: September 2026
Our Position, Stated Plainly
ExaVeyra Sciences is not a HIPAA covered entity. We are not a health plan, a health care clearinghouse, or a health care provider transmitting health information in HIPAA-covered transactions. We are a wholesale distributor supplying licensed practices, and we do not practice medicine or treat patients.
We state this directly because the alternative claim is common in this category and rarely accurate. A supplier that advertises itself as HIPAA compliant is usually describing a standard that does not apply to it. What follows is what actually applies to us, and what we will commit to when it does.
What This Means for Practices
We do not request Protected Health Information, and we ask that you not send it. This includes patient names, records, diagnoses, images, and any information about an identifiable patient. Our ExaBot assistant displays this instruction before every conversation, and it applies equally to email, forms, and phone calls.
Ordering, credential verification, and technical support run on practice-level information: clinic or entity name, National Provider Identifier, state license details, and shipping addresses. None of that is PHI, and all of it is handled under our Privacy Policy.
If PHI reaches us despite this, we limit access to it, use it only to resolve the matter it was sent about, and delete it once resolved.
What This Means for Individuals
ExaVeyra does not provide telehealth consultations, concierge medicine, or any other clinical service. Individuals who ask to be connected with care are routed to independent licensed providers in their state. Those providers conduct the consultation, own the clinical relationship, and make every clinical decision.
The information you give us in a referral request, your name, contact details, your state, and the fact that you asked to be connected, is not PHI in our hands, because no covered entity relationship exists at that point. It is handled under our Privacy Policy and under the state health privacy laws that apply to entities outside HIPAA. Once you are connected, the provider's own privacy practices govern the clinical relationship.
Business Associate Agreements
Where a specific arrangement means we perform a function or activity on behalf of a covered entity that involves PHI, that arrangement makes us a Business Associate under 45 C.F.R. Parts 160 and 164. In that situation we will execute a Business Associate Agreement before the work begins, and we will handle the information under that agreement's terms rather than under this page. A BAA we sign would address:
- Permitted uses and disclosures of PHI
- Safeguards to protect PHI
- Reporting of security incidents and breaches
- Subcontractor obligations when PHI is shared
- Return or destruction of PHI upon termination
- Access to information for individual rights requests
To request a BAA or discuss whether one applies to your arrangement, contact us via our Contact page. Requests are reviewed by the founder, who is also the point of contact for any question on this page.
Safeguards We Maintain
These apply to all information we hold, whether or not HIPAA reaches it. We list only what we actually do.
- Workforce training: Personnel who could encounter health information receive HIPAA awareness training and are bound by confidentiality obligations.
- Minimum necessary: We limit access and disclosure to the minimum needed to accomplish the purpose at hand.
- Encryption: Information in transit is protected with TLS. Information at rest is encrypted using industry-standard methods.
- Access controls: Unique user identification, role-based access, and row-level security policies limit who can view or modify records.
- Least privilege: Administrative access is granted only where a role requires it and is reviewed when roles change.
We do not maintain patient records in physical form. Our technology vendors are engaged under contract and are not permitted to use information for their own purposes; where any vendor would process PHI on our behalf, we require a BAA or equivalent assurance before that processing begins.
Breach Notification
If information we hold is compromised, our obligations depend on what the information is and how we hold it.
- Where we hold PHI as a Business Associate, we notify the covered entity without unreasonable delay and no later than 60 days after discovery, so that it can meet its own notification obligations under HIPAA.
- Where the information is personal information rather than PHI, we notify affected individuals and the appropriate authorities as required by Fla. Stat. 501.171 and the breach notification law of the affected person's state.
- We cooperate with any covered entity, provider, or regulator involved in responding to the incident.
Individual Rights
Where we hold PHI on behalf of a covered entity, individual rights including access, amendment, accounting of disclosures, restrictions, and confidential communications are exercised through that covered entity, and we support it in fulfilling those requests. For everything else we hold, your rights are described in our Privacy Policy, which sets out how to make a request and how quickly we respond.
Questions & Contact
For questions about how we handle health information, BAA requests, or security concerns, contact us via our Contact page.