Privacy Notice

NXi Systems — Nexus. Last updated 25 July 2026.

What Nexus is

Nexus is a directory of service providers (law offices, clinics, vocational counselors and similar) and a broker for referrals between them. Providers register, are approved by NXi staff, and become searchable by provider type, service type and region.

What Nexus holds about a patient or plaintiff

Nexus is deliberately built to hold as little as possible about the people referred through it. It does not store patient or plaintiff names, dates of birth, Social Security numbers, medical record numbers, addresses, or any clinical record.

Instead, a referral's subject is recorded as a keyed handle — an irreversible cryptographic value derived from the referring provider's own internal client identifier. Nexus cannot turn that handle back into a person. Only the provider who created the referral can do so.

Nexus does record, for each referral: which two providers are involved, which service was referred for, the status of the referral, and the authorization (consent) that permits information to be exchanged.

How records actually move

Records are not uploaded to or stored by Nexus. When an exchange is authorized, Nexus issues a short-lived, single-purpose grant, and the receiving provider uses it to obtain records directly from the sending provider. No clinical documents pass through or rest on Nexus.

Authorization and revocation

Information may only be exchanged when the patient or plaintiff has authorized it, and that authorization is captured when the referral is created — not afterwards. An authorization is limited in scope (to named providers, a named service, and an expiry date) and may be revoked at any time. Once revoked, no further grants are issued and outstanding grants stop working.

Record of disclosures

Nexus keeps a permanent, append-only record of every authorization event: each grant issued, redeemed, denied, or revoked. This record supports an accounting of disclosures under HIPAA §164.528. Because Nexus holds no patient identifiers, a request for such an accounting is fulfilled jointly: your provider identifies the relevant handle, and Nexus supplies the events recorded against it.

Staff access

Access by NXi staff requires two-factor authentication. There are no passwords; sign-in uses a rotating code from an authenticator app. Sessions end automatically after a short period of inactivity and have a hard maximum lifetime. Access is limited to staff whose role requires it, and access to the disclosure record is separately restricted.

Provider access

Approved providers reach Nexus through an authenticated machine interface. Each credential is bound to exactly one provider, which may read the public directory and only its own referrals, authorizations and grants — never another provider's.

Your rights

California residents have rights under the Confidentiality of Medical Information Act (CMIA) and, where applicable, the CCPA/CPRA, including rights of access, correction and deletion. Because Nexus holds no direct identifiers, please direct such requests to the provider who holds your record; they can identify the relevant entries and, where appropriate, ask us to act.

Contact

Questions about this notice may be sent to NXi Systems through the provider that referred you, or to the address published by your NXi account contact.

Back to Nexus