HIPAA
Protecting Protected Health Information (PHI)
Last Updated: January 1, 2026
Lextiff is designed with security, privacy, and administrative safeguards intended to support law firms that handle sensitive client information, including Protected Health Information (PHI).
Because plaintiff litigation frequently involves medical records, treatment histories, insurance documentation, and other confidential healthcare information, protecting the confidentiality, integrity, and availability of customer data is a fundamental part of how we design and operate the Lextiff platform.
While no software product alone can make an organization HIPAA compliant, Lextiff provides security features and operational safeguards intended to help customers meet their own compliance responsibilities.
Important Notice
The information on this page is provided for general informational purposes only.
Nothing contained on this page constitutes legal advice or represents that Lextiff, by itself, satisfies all requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
HIPAA compliance depends on many factors outside of software, including an organization's policies, workforce training, administrative safeguards, operational procedures, and regulatory obligations.
Customers are responsible for determining whether HIPAA applies to their organization and for complying with all applicable healthcare privacy and security laws.
Designed for Plaintiff Law Firms
Lextiff is built specifically for plaintiff law firms that routinely work with sensitive medical and legal information throughout the lifecycle of a case. Depending on how the platform is used, customers may manage information such as:
- • Medical records
- • Treatment histories
- • Hospital documentation
- • Insurance claim information
- • Diagnostic reports
- • Prescription records
- • Medical imaging
- • Rehabilitation records
- • Settlement documentation
- • Physician correspondence
- • Expert reports
- • Client communications
Customer Data remains the property of the Customer at all times. Lextiff does not sell Customer Data and does not use client matter information for advertising or marketing purposes.
Security Designed for Sensitive Information
Lextiff incorporates layered security controls intended to protect Customer Data throughout the platform. Security measures may include:
- ✓ Encryption of data transmitted over public networks using Transport Layer Security (TLS)
- ✓ Encryption of stored data where applicable
- ✓ Role-Based Access Control (RBAC)
- ✓ Firm-level data isolation
- ✓ Branch-level permissions
- ✓ Secure authentication
- ✓ Password hashing using industry-accepted algorithms
- ✓ Optional Multi-Factor Authentication (MFA)
- ✓ Audit logging
- ✓ Infrastructure monitoring
- ✓ Automated backups
- ✓ Disaster recovery planning
- ✓ Incident response procedures
- ✓ Secure cloud infrastructure
Security controls are reviewed and improved as technology, industry standards, and operational requirements evolve.
Protected Health Information (PHI)
Customers may choose to store or process Protected Health Information ("PHI") through the Services where appropriate for their legal practice. Examples may include:
- • Medical records
- • Treatment documentation
- • Physician notes
- • Insurance information
- • Medical billing records
- • Diagnostic reports
- • Imaging records
- • Prescription information
- • Rehabilitation documentation
- • Medical correspondence
- • Injury documentation
Lextiff processes such information solely for the purpose of providing and supporting the Services in accordance with the Customer's instructions and applicable agreements.
Shared Responsibility
Protecting Protected Health Information is a shared responsibility. While Lextiff is responsible for maintaining the security of the platform, Customers remain responsible for the lawful use of the Services and for their own compliance obligations.
Lextiff Responsibilities
- • Secure cloud infrastructure
- • Platform security controls
- • Access management capabilities
- • Security monitoring
- • Audit logging
- • Backup and recovery procedures
- • Incident response processes
- • Vendor management
- • Ongoing security improvements
Customer Responsibilities
- • Determining whether HIPAA applies to their organization
- • Obtaining any required patient authorizations or consents
- • Configuring user permissions appropriately
- • Maintaining secure devices and networks
- • Workforce HIPAA training
- • Password management
- • Internal security policies
- • Responding to security incidents within their organization
- • Compliance with applicable healthcare laws, professional obligations, and regulatory requirements
Business Associate Agreement (BAA)
Where required by applicable law, Lextiff is prepared to enter into a separate Business Associate Agreement (BAA) with eligible Customers. The BAA establishes each party's responsibilities regarding the handling of Protected Health Information and supplements the Lextiff Terms of Service, Privacy Policy, and Data Processing Addendum.
Execution of a BAA does not, by itself, establish HIPAA compliance. Both Lextiff and the Customer remain responsible for fulfilling their respective obligations under applicable law.
Customers who require a Business Associate Agreement may contact our Privacy Team for additional information.
Request a BAA →Incident Response
Lextiff maintains documented incident response procedures designed to:
- • Detect potential security events
- • Investigate reported incidents
- • Contain and mitigate confirmed security incidents
- • Restore affected systems
- • Notify affected Customers where required by applicable law or contractual obligations
- • Review and improve security controls following significant incidents
If Lextiff becomes aware of a confirmed security incident affecting Customer Data, we will respond in accordance with our contractual obligations, applicable law, and our documented incident response procedures.
Vendor Management
Lextiff works with carefully selected third-party service providers to support the operation of the Services.
Where applicable, vendors that process Customer Data are evaluated for their security, operational, and privacy practices and are required to maintain contractual obligations appropriate to the services they provide.
Additional information regarding our service providers is available in our Subprocessor List.
Privacy & Data Protection
Lextiff's privacy and security program is supported by a comprehensive set of policies and agreements, including:
Frequently Asked Questions
HIPAA does not provide an official certification program for software vendors. Instead, Lextiff is designed with security and privacy safeguards intended to support organizations that are subject to HIPAA.
Yes. Where required by applicable law, Lextiff is prepared to execute a Business Associate Agreement (BAA) with eligible Customers.
Lextiff uses industry-standard encryption technologies for data transmitted over public networks and employs encryption for stored data where applicable.
Lextiff personnel do not routinely access Customer Data. Access is limited to authorized personnel with a legitimate business need, such as providing technical support, maintaining the Services, or complying with applicable legal obligations, and is subject to appropriate confidentiality obligations.
Customer Data remains the property of the Customer. Lextiff does not claim ownership of Customer Data and processes Customer Data only for the purpose of providing and supporting the Services.
Contact Us
Questions regarding HIPAA, privacy, or Business Associate Agreements may be directed to:
Privacy Team
privacy@lextiff.comSecurity Team
security@lextiff.com