Data Compliance

NXi Systems — Nexus. Last updated 25 July 2026.

This page describes the specific safeguards Nexus implements, in the language of the rules they answer to. It is written to be checkable — each item corresponds to something implemented in the system, not an aspiration.

Scope: what makes this PHI

A referral records that an identifiable individual sought or received a service. That is protected health information even with no clinical content attached, so HIPAA and the California Confidentiality of Medical Information Act (CMIA) apply to Nexus in full.

Data minimization (HIPAA §164.502(b), minimum necessary)

Authorization for disclosure (HIPAA §164.508; CMIA §56.11)

Accounting of disclosures (HIPAA §164.528)

Automatic logoff (HIPAA §164.312(a)(2)(iii); CMIA §56.101)

Access control (HIPAA §164.312(a)(1), §164.312(d))

Transmission and integrity (HIPAA §164.312(e))

Error reporting and PHI

Browser hardening

Deliberately out of scope

Nexus does not offer record storage or store-and-forward delivery. Adding it would make Nexus a repository of clinical information and would change the analysis on this page substantially. It is excluded by design, not omitted by oversight.

Back to Nexus