Last updated · July 2026
Business Associate Addendum
This BAA framework describes how Helixir supports customers who are HIPAA covered entities or their business associates. A signed BAA is required before Helixir may process Protected Health Information (PHI) on behalf of a covered entity; contact info@nevika.co to request one.
Scope of PHI in the platform
Helixir does not require PHI at signup and does not display PHI to any user outside the customer’s own organization. When a user submits free-text into an AI workflow, Helixir applies a server-side identifier-redaction step before the prompt leaves our infrastructure.
Permitted uses and disclosures
Helixir uses PHI only to provide the platform to the customer and as permitted by the signed BAA. Helixir does not sell PHI and does not permit sub-processors to use PHI for their own purposes, including model training.
Safeguards
Row-level security, per-organization scoping, immutable audit logging of AI activity, encryption in transit, rate limits, and least-privilege access controls for Helixir personnel.
Breach notification
Helixir will notify the customer without unreasonable delay, and no later than the timeframe stated in the signed BAA, upon discovery of a breach of Unsecured PHI.
Subcontractors
Helixir will require its subcontractors that handle PHI to enter into written agreements imposing restrictions substantially similar to those in the signed BAA.
Termination and return of PHI
On termination, Helixir will return or destroy PHI as instructed by the customer, or, where infeasible, extend the protections of the BAA to any PHI retained.
Not legal advice
This page is a summary. Only a signed BAA between the customer and Helixir creates enforceable obligations.