Legal & Compliance

HIPAA Notice & Compliance Statement

Last updated: July 2026

Healthcare credentialing services — Niyutsa Technologies

Our Commitment to HIPAA Compliance

Niyutsa Technologies LLC provides healthcare provider credentialing and payer enrollment services and, in the course of that work, may receive, process, or transmit information related to healthcare providers as part of enrollment applications submitted to Medicare, Medicaid, and commercial insurance payers. We are committed to protecting this information in accordance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the HITECH Act, and applicable state privacy laws.

Business Associate Agreements

For every client engagement that involves the handling of protected health information (PHI) or PHI-adjacent provider data, Niyutsa Technologies executes a signed Business Associate Agreement (BAA) prior to beginning work. This agreement defines the permitted uses and disclosures of PHI, the safeguards we maintain, and our obligations in the event of a breach, consistent with 45 CFR §164.504(e).

White-label partners (medical billing companies, RCM firms, and healthcare BPO companies) that route client credentialing work through Niyutsa Technologies are covered under the same BAA framework — we act as a downstream business associate with respect to the underlying provider data, and our partnership agreements are structured to maintain HIPAA compliance across the full chain of custody.

Administrative, Technical, and Physical Safeguards

Administrative safeguards include designated security responsibility, workforce training on HIPAA requirements and confidentiality obligations, access authorization procedures limiting PHI access to staff actively working on a given engagement, and incident response procedures.

Technical safeguards include encryption of data in transit and at rest, unique user authentication and access logging, automatic session timeouts, and regular review of system access.

Physical safeguards include restricted facility access and secure workstation policies for any staff handling provider information, whether in our Dallas, Texas headquarters or our Delhi, India delivery office.

Minimum Necessary Standard

Consistent with HIPAA's minimum necessary standard, we limit the collection, use, and disclosure of PHI and provider information to what is reasonably necessary to complete the specific credentialing or payer enrollment task at hand. We do not use provider information for any secondary purpose, including marketing, without explicit authorization.

Subcontractors and Downstream Disclosures

Where Niyutsa Technologies engages subcontractors who may have access to PHI in the course of supporting our credentialing operations, we require those subcontractors to agree to protections at least as stringent as those in our own BAAs, consistent with HIPAA's requirements for downstream business associates.

Breach Notification

In the unlikely event of a breach involving unsecured PHI, Niyutsa Technologies will notify affected clients without unreasonable delay and in accordance with the timelines and requirements set forth in the HITECH Act's breach notification rule and the terms of the applicable BAA.

Reporting a Concern

If you believe your protected health information has been used or disclosed inappropriately in connection with our services, or if you have any HIPAA-related question or concern, please contact us immediately at info@niyutsatechnologies.com or (858) 223-7899.

Related Policies

This HIPAA Notice should be read together with our Privacy Policy and Terms of Use, which govern our broader collection and use of information.

FAQ

HIPAA compliance questions

Is Niyutsa Technologies HIPAA compliant?

Yes. Niyutsa Technologies maintains administrative, technical, and physical safeguards consistent with the HIPAA Security Rule and Privacy Rule, and executes a signed Business Associate Agreement (BAA) with every client whose engagement involves protected health information.

What is a Business Associate Agreement (BAA)?

A BAA is a contract required under HIPAA between a covered entity (such as a healthcare provider or practice) and a business associate (such as Niyutsa Technologies) that performs services involving protected health information on the covered entity's behalf. It defines how PHI may be used, disclosed, and protected.

What information does Niyutsa Technologies consider PHI?

In the context of credentialing, PHI-adjacent provider information can include license numbers, malpractice claims history, work history, and other identifying details submitted as part of an enrollment application. We treat this information with the same safeguards as PHI regardless of its precise legal classification.

How does Niyutsa Technologies secure provider information?

We use encrypted data transmission and storage, role-based access controls limiting information access to staff directly working on a given engagement, audit logging, and staff training on HIPAA requirements and confidentiality obligations.