Skip to content
Juris 340B Solutions
Legal · read by procurement teams

HIPAA & Data-Handling Statement

A plain-language summary of how PHI and other sensitive data are handled across every engagement. We hand over the full data map during procurement without being asked.

Our posture

What governs every engagement

This is a summary of our operating controls, not a substitute for the signed Business Associate Agreement (BAA) executed with every client whose engagement involves PHI.

  • 01A named, US-based, Apexus ACE-certified clinical lead owns every engagement and every finding
  • 02PHI is hosted in US infrastructure under a signed Business Associate Agreement with our cloud provider — data does not leave US infrastructure
  • 03Wherever the work permits, data is de-identified using the HIPAA Safe Harbor method before analysis begins
  • 04Any team member with data access completes documented HIPAA training, logged annually, under a written sanctions policy
  • 05We sign a Business Associate Agreement with every client whose engagement involves PHI, and flow down equivalent obligations to any subcontractor
The short version

PHI stays on US infrastructure, always.

A named, ACE-certified US clinical lead owns every engagement — and we hand over the full data map before you have to ask.

Security certification

[PLACEHOLDER — confirm current SOC 2 status before publishing a specific claim. Do not state a certification has been achieved unless it has been independently audited and confirmed.]

VERIFY BEFORE PUBLICATION: this page is a structural draft, not reviewed or approved legal language. It must be reviewed by qualified US healthcare/privacy counsel before the site goes live, and updated with the firm's actual registered entity name, jurisdiction and contact details.

Next step

Request our full data map.

We provide a one-page data-handling statement during procurement — ask for it directly.

Talk to an Expert