Scope and compliance

Trust

This is the canonical statement of what Nextora will and will not claim on HIPAA, business associate agreements, and FDA submissions. The solutions page lists which engagement shapes need a BAA; this page is the policy.

HIPAA and business associate agreements

Nextora does not call software “HIPAA-compliant.” Compliance is a property of your whole environment—policies, access control, risk analysis, and the agreements around them—not a feature of a deliverable.

If an engagement requires Nextora to create, receive, maintain, or transmit protected health information on your behalf, a Business Associate Agreement is signed before any identifiable data moves. Architecture, staging work, and de-identified extracts can proceed without one when identifiable data never reaches us.

What needs a BAA, in detail

FDA submissions and clinical validation

Nextora does not take FDA submissions, device classification, or formal clinical validation of software as a medical device. If that is the work, we will say so early and point you toward a specialist rather than take the engagement.

You keep the system

Engagements end with the code in your repository, documentation, and a runbook your team can operate. Follow-on work is optional.

Tell us what you are trying to fix