Business Associate Privacy Practices

Effective: July 28, 2026 · Version 1.0

This statement describes how Axeum handles Protected Health Information as a HIPAA Business Associate across the axeumCARE product family. It is intended for the healthcare practices and organizations that use these products and their advisors — it is not a patient-facing notice.

Who We Are and Our Role

Axeum Technologies, Inc. ("Axeum") provides governed provider intelligence through the axeumCARE product family, its healthcare sub-vertical. This includes axeumFLOW (the digital SaaS platform operated at care.axeumai.com) and its companion products axeumAURA, axeumCOMPANION, and axeumSENSE. Where any axeumCARE product processes health information on behalf of a healthcare practice or organization, Axeum acts as a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health (HITECH) Act. This statement applies to all axeumCARE products.

The healthcare practice is the Covered Entity. The practice is responsible for the care of its patients and for issuing its own Notice of Privacy Practices to those patients. Axeum does not have a direct relationship with patients and does not issue notices to them. This statement explains how Axeum handles the health information it receives from a practice in order to support that practice's operations.

What Health Information We Process

Axeum receives and processes Protected Health Information (PHI) that a practice shares with it to deliver services, including: appointment and scheduling data; clinical documentation and encounter notes; diagnosis and procedure codes; insurance and billing information; remittance and payment data; and remote patient monitoring data where applicable.

Axeum applies the minimum-necessary standard — it accesses and uses only the PHI required to perform the specific service the practice has engaged it to deliver.

How We Use and Disclose Health Information

Axeum uses PHI only as permitted under its Business Associate Agreement with the practice and applicable law:

What We Will Not Do

Axeum will not: sell PHI; use it for marketing purposes; use it to train AI models without explicit authorization; or disclose it for any purpose not permitted under its Business Associate Agreement with the practice.

Patient Rights

Because Axeum is a Business Associate and has no direct relationship with patients, all patient rights under HIPAA — access to records, amendment, an accounting of disclosures, and restriction requests — are exercised through the patient's healthcare practice, the Covered Entity. Axeum supports the practice in fulfilling those requests as required under the Business Associate Agreement.

Security

Axeum implements administrative, physical, and technical safeguards consistent with the HIPAA Security Rule (45 C.F.R. §§164.308–164.318), including: encrypted data transmission and storage; tenant-scoped data isolation; append-only cryptographically signed audit records; role-based access controls; and automatic session timeout.

Contact

For questions about this statement or Axeum's privacy practices:
Axeum Technologies, Inc.
Privacy Officer: Stephen Piscitelli
privacy@axeumai.com

Changes to This Statement

Axeum reserves the right to change this statement. The current version will always be available at axeumai.com/hipaa-notice.html.