HIPAA Compliance & Privacy Policy
Effective Date: September 1, 2026 • Version 2.4 • Medinext Global LLC
1. Commitment to HIPAA & Protected Health Information (PHI)
Medinext Global LLC ("Medinext", "we", "our", or "us") is dedicated to upholding the highest standards of data security, confidentiality, and regulatory integrity in the healthcare industry. We operate in strict compliance with the Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, the Health Information Technology for Economic and Clinical Health (HITECH) Act, and the HIPAA Omnibus Final Rule.
When providing Recruitment Process Outsourcing (RPO), specialized IT staffing, healthcare talent acquisition, clinical workforce staffing, and enterprise IT solutions, Medinext processes Protected Health Information (PHI) and workforce data exclusively on behalf of Covered Entities and corporate clients in our capacity as a Business Associate and trusted technology partner.
2. Business Associate Agreement (BAA) Obligations
In compliance with 45 CFR § 164.502(e) and § 164.504(e), Medinext executes legally binding Business Associate Agreements (BAAs) with all healthcare clients prior to receiving, transmitting, or processing any electronic PHI (ePHI). Under our standard BAA obligations:
- We will not use or disclose PHI other than as permitted or required by the agreement or as required by law.
- We implement appropriate administrative, physical, and technical safeguards to prevent unauthorized use or disclosure of ePHI.
- We report any security incident or unauthorized access/breach to the Covered Entity within twenty-four (24) hours of discovery.
- We ensure that all subcontractors and global delivery personnel who create, receive, maintain, or transmit ePHI agree to identical restrictions and conditions.
3. Technical, Physical & Administrative Safeguards
Medinext employs a defense-in-depth Zero-Trust security posture governed under HIPAA and enterprise data protection standards:
AES-256 bit encryption at rest for all database volumes; TLS 1.3 encryption for all data in transit across public and private networks.
Strict role-based access control (RBAC), multi-factor authentication (MFA), and session timeout policies enforced across all systems.
Continuous 24/7 Security Information and Event Management (SIEM) monitoring with immutable logging of all PHI access events.
Mandatory background checks, annual HIPAA certification testing, and clean-desk zero-local-storage workstation policies.
4. Information Governance & Data Collection
We collect information directly from you when you submit an executive consultation request on our website (such as full name, email address, telephone number, and organization name), as well as candidate credentials, staffing records, and project data provided by authorized clients under executed agreements and BAAs.
We do not sell, rent, monetize, or trade candidate data, client contact lists, or analytics to third-party advertisers or data brokers under any circumstances.
5. User Privacy Rights (GDPR & CCPA / CPRA)
Depending on your jurisdiction, you may have specific statutory privacy rights regarding your personal information under the California Consumer Privacy Act (CCPA/CPRA) or the General Data Protection Regulation (GDPR), including:
- Right to Know & Access: You may request disclosure of the categories and specific pieces of personal information collected.
- Right to Rectification: You may request correction of inaccurate personal contact data.
- Right to Deletion: You may request deletion of your corporate contact information, subject to mandatory legal and financial audit retention requirements.
- Non-Discrimination: We will not discriminate against any user for exercising their statutory privacy rights.
6. Data Retention & Media Sanitization
Client workforce data, placement records, and engagement files are retained in accordance with applicable federal, CMS, and state workforce record retention guidelines (typically a minimum of seven years). Upon contract conclusion, data is transferred securely or permanently sanitized following NIST SP 800-88 Rev. 1 Guidelines for Media Sanitization.
7. Contact the Data Privacy & Security Office
For questions regarding this policy, HIPAA compliance attestations, or to report a security concern, please contact our Chief Information Security Officer (CISO) and Data Protection Officer (DPO):
Medinext Global LLC — Privacy & Information Security Office
Attn: Elena Rostova, MS, CISSP (CISO & Privacy Officer)
Address: 30 N Gould St, Ste R, Sheridan, WY 82801
Email: info@medinextglobal.com
Phone: 862-799-2199
Ready to Scale Your Workforce & Analytical Capacity?
Schedule a confidential workforce strategy consultation with our senior talent acquisition and enterprise workforce specialists.