Home / Services / HIPAA deployment
HIPAA compliance & BAA

HIPAA-compliant technology, deployed inside your boundary

Most home health agencies do not need a bigger IT stack. They need the tools they already pay for configured properly, the repetitive work automated, and AI added only where it is safe and worth it. We build that, document it, and hand it over.

What “HIPAA-compliant” means here

Compliance is how a system is run, not a label on the box

HIPAA does not certify software. A vendor can sign a Business Associate Agreement and still be configured in a way that leaks. Compliance is a property of how a covered entity and its business associates set up, operate and document their systems.

So we do three things on every engagement:

  • Put technical safeguards in place that match the HIPAA Security Rule (45 CFR 164.312): access control, audit controls, integrity, authentication and transmission security.
  • Produce the documentation your compliance officer needs for the risk analysis, policies and procedures (164.308 and 164.316).
  • Train the people who use it, and keep a record that you did (164.308(a)(5)).

What we do not do. We do not decide what your agency must do under HIPAA or California law, certify anything, or replace your compliance officer or counsel. We build and document the technical side so they can make those calls with evidence in front of them.

A smiling nurse and an older patient sitting close together at home
Home health runs on trust. The systems behind it should earn the same.
What we deploy

Eight things we build, configure and hand over

Most engagements start with one of these and grow only if the first one earns it.

Secure Microsoft 365 foundation

Sign-in with multi-factor authentication, groups built around who needs what, governed guest access, retention and audit logging. The boring layer that every other control depends on.

Policy and regulation assistants

Closed-book assistants in Microsoft Teams that answer only from your own handbook, policies and the regulations you load, with the source cited, and say plainly when the documents do not cover a question.

Workflow automation

Credential and license tracking, vendor invoice audits, route-sheet and payroll close, order filing: the repetitive office work that eats a week every month, run on a schedule with exceptions reported.

Document intake on encrypted hardware

Scanned forms, orders and photos read, matched to the right record and filed, with the reading done on encrypted machines you control and a person confirming anything uncertain.

Compliance dashboards and audit trail

One place to see what ran, what it found and who needs to act, built on lists and reports your staff already open. Every automated run leaves an append-only record.

Phone and communications

Teams Phone attendants and call queues, voicemail turned into tracked tasks, so a message left at 7 p.m. is a visible item at 8 a.m., not a blinking light.

Continuous compliance checks

Monthly exclusion screening, credential boards, and a watcher that tells you when the regulation or manual your policies cite has changed.

Runbooks, SOPs and evidence

Everything we deploy is documented well enough that someone else could run it. Your compliance officer gets the data-flow map, access roster and test evidence for the risk analysis.

Where PHI stays

One rule shapes every design: the boundary

Before we pick a tool, we draw the boundary: which systems are yours, which accounts are named, which hardware is encrypted. PHI stays inside it. Assistants answer from documents you own, and anything that leaves is not PHI, or never was.

Where PHI stays Staff with named accounts ask a closed-book assistant that answers only from the agency's own documents, all inside the agency's boundary with an audit trail. Public AI chat tools and personal email sit outside the boundary and never receive PHI. INSIDE YOUR BOUNDARY Your Microsoft 365 tenant and encrypted hardware you control Your staff Named accounts Multi-factor sign-in Closed-book assistant Cited answers only Your documents Policies, SOPs, regulations Audit trail on everything Every automated run is logged. A person confirms before anything is filed. Public AI chat tools Consumer apps and sites Personal email, texts Unmanaged channels OUTSIDE PHI never goes here
The shape of a typical deployment. Your own documents are the only knowledge the assistant has. That is also how AI gets approved in practice: not “is this model safe?” but “what data can this tool see, and where does it run?”
The data-class rule

Which AI may touch which data

A one-page rule your staff can actually follow. We write it with you, then enforce it in how the tools are set up.

Class of dataWhere AI may runExample
Public or marketingAny approved vendorDrafting a job posting or a newsletter
Agency-internal, no PHIA closed-book assistant in your Microsoft 365 tenant, with web search and outside answers turned off“What does our policy say about order signatures?”
Contains PHIOnly inside your tenant under a Business Associate Agreement, or on encrypted hardware you control. A person confirms before anything is filedReading a scanned order to find the right patient folder
Decisions about care, eligibility or billingAI may propose; an authorized person decides and signsFlagging a visit that may not match its plan of care
How an engagement runs

Four steps, each with something you can inspect

  1. Assess

    Map the work and the data

    A working session on one process: who does it, how often, where PHI appears, what “fixed” would mean in numbers. We tell you plainly whether AI belongs in it, and often it does not.

  2. Pilot

    Build one workflow for real

    On your systems, with your data rules, measured against the baseline we wrote down in step one. No demos that only run on a laptop.

  3. Harden

    Lock it down and write it down

    Access reviewed, logging switched on, failure cases tested, runbook written. Your compliance officer receives the evidence.

  4. Hand over

    Train your people and stay on call

    Staff are trained on the new workflow, you decide whether to run it yourselves or keep us on a support plan, and we stay available either way.

What your compliance file gets

  • A data-flow map: where PHI is created, stored, moved and deleted
  • An access roster and group structure, with the reason for each grant
  • An inventory of vendors and sub-processors, and which are covered by a BAA
  • Runbooks and SOPs for every automated process
  • Test evidence: what we checked, how, and the result
  • Training records: who learned what, when

California on top of HIPAA

Home health in California answers to more than one rule book. We design for these from the start:

  • The California Confidentiality of Medical Information Act, which sits alongside HIPAA and is stricter in places
  • CDPH licensing: Title 22, California Code of Regulations, Division 5, Chapter 6, and Health and Safety Code sections 1725 to 1742
  • The Medicare Conditions of Participation, 42 CFR Part 484, including patient rights and clinical records
  • Accreditation standards such as ACHC, if your agency holds them

Each of these shapes what must be kept, signed within what time, and produced on demand during a survey. Our systems are built to produce that evidence.

Business Associate Agreements

BAAs run in both directions. We help with both.

A Business Associate Agreement is the contract that lets a vendor touch PHI on your behalf, and it must exist before the PHI moves (45 CFR 164.502(e) and 164.504(e)). Most agencies have more business associates than they realize: the EMR, the cloud mailbox, the phone system, the shredding company, the billing service, the IT provider.

  • Vendor inventory. We list every system and vendor that creates, receives, stores or transmits PHI, and mark which have a signed BAA and which do not.
  • Gap list. Missing agreements, expired ones, and vendors whose product tier does not include one (some features and plans are excluded from a vendor’s BAA).
  • A tracking sheet. Renewal dates, contacts and where each signed copy lives, so the answer to “do we have a BAA with them?” takes seconds.
  • Algorixtec as your business associate. When our work touches PHI, we work under a BAA between your agency and Algorixtec, with the minimum necessary access.

Counsel signs off on the wording. We inventory, track and flag. Your attorney reviews the agreement text, and your compliance officer decides what is acceptable.

The HIPAA file we help you build

  • Risk analysis inputs: assets, data flows, vulnerabilities (from our scans) and existing controls
  • Policies and procedures that match what is really done
  • Workforce training records, from our training
  • Breach-response plan, including the ransomware case (see our ransomware defense)
  • Contingency plan with restore tests
  • The BAA inventory above
Questions agencies ask first

Straight answers

Do you need access to our patient records?

Often not. Many builds can be designed and tested on de-identified samples, or run inside your own Microsoft 365 tenant with named accounts so the data never moves. Where access to PHI is needed, it happens under a Business Associate Agreement, limited to the minimum necessary, and logged.

Can our staff just use ChatGPT or Copilot?

Consumer chat tools should never receive PHI. Tools that run inside your Microsoft 365 tenant, under your Microsoft agreement, can be appropriate once they are configured properly: for example, assistants with web search and outside answers switched off so they can only quote your own documents. Configuration is where most of the risk is, and where we spend most of our time.

Will AI make decisions about our patients or our billing?

No. AI may read, sort, flag and draft. An authorized person decides and signs. Anything an AI reads from a document is treated as a proposal until a person confirms it.

What if you build something and we want to stop using you?

Everything is documented so someone else can run it, and it lives in your accounts or on hardware you control wherever possible. You should never be locked in by what we build. That is a design requirement, not a favor.

Do you sign a Business Associate Agreement?

Yes. Where an engagement involves PHI, work starts from a Business Associate Agreement between your agency and Algorixtec.

What does it cost?

It depends on scope, so we do not publish a rate card. The first step is a working session on one process, after which you get a fixed-scope proposal for a pilot.

Tell us the one workflow that costs you the most time.

A working session is free of obligation: we look at one process, tell you plainly whether AI belongs in it, and what keeping it inside HIPAA would take.

Book a working session