Compliance

HIPAA

Protecting Protected Health Information (PHI)

Last Updated: January 1, 2026


Lextiff is designed with security, privacy, and administrative safeguards intended to support law firms that handle sensitive client information, including Protected Health Information (PHI).

Because plaintiff litigation frequently involves medical records, treatment histories, insurance documentation, and other confidential healthcare information, protecting the confidentiality, integrity, and availability of customer data is a fundamental part of how we design and operate the Lextiff platform.

While no software product alone can make an organization HIPAA compliant, Lextiff provides security features and operational safeguards intended to help customers meet their own compliance responsibilities.

Important Notice

The information on this page is provided for general informational purposes only.

Nothing contained on this page constitutes legal advice or represents that Lextiff, by itself, satisfies all requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

HIPAA compliance depends on many factors outside of software, including an organization's policies, workforce training, administrative safeguards, operational procedures, and regulatory obligations.

Customers are responsible for determining whether HIPAA applies to their organization and for complying with all applicable healthcare privacy and security laws.

Designed for Plaintiff Law Firms

Lextiff is built specifically for plaintiff law firms that routinely work with sensitive medical and legal information throughout the lifecycle of a case. Depending on how the platform is used, customers may manage information such as:

  • Medical records
  • Treatment histories
  • Hospital documentation
  • Insurance claim information
  • Diagnostic reports
  • Prescription records
  • Medical imaging
  • Rehabilitation records
  • Settlement documentation
  • Physician correspondence
  • Expert reports
  • Client communications

Customer Data remains the property of the Customer at all times. Lextiff does not sell Customer Data and does not use client matter information for advertising or marketing purposes.

Security Designed for Sensitive Information

Lextiff incorporates layered security controls intended to protect Customer Data throughout the platform. Security measures may include:

  • Encryption of data transmitted over public networks using Transport Layer Security (TLS)
  • Encryption of stored data where applicable
  • Role-Based Access Control (RBAC)
  • Firm-level data isolation
  • Branch-level permissions
  • Secure authentication
  • Password hashing using industry-accepted algorithms
  • Optional Multi-Factor Authentication (MFA)
  • Audit logging
  • Infrastructure monitoring
  • Automated backups
  • Disaster recovery planning
  • Incident response procedures
  • Secure cloud infrastructure

Security controls are reviewed and improved as technology, industry standards, and operational requirements evolve.

Protected Health Information (PHI)

Customers may choose to store or process Protected Health Information ("PHI") through the Services where appropriate for their legal practice. Examples may include:

  • Medical records
  • Treatment documentation
  • Physician notes
  • Insurance information
  • Medical billing records
  • Diagnostic reports
  • Imaging records
  • Prescription information
  • Rehabilitation documentation
  • Medical correspondence
  • Injury documentation

Lextiff processes such information solely for the purpose of providing and supporting the Services in accordance with the Customer's instructions and applicable agreements.

Shared Responsibility

Protecting Protected Health Information is a shared responsibility. While Lextiff is responsible for maintaining the security of the platform, Customers remain responsible for the lawful use of the Services and for their own compliance obligations.

Lextiff Responsibilities

  • Secure cloud infrastructure
  • Platform security controls
  • Access management capabilities
  • Security monitoring
  • Audit logging
  • Backup and recovery procedures
  • Incident response processes
  • Vendor management
  • Ongoing security improvements

Customer Responsibilities

  • Determining whether HIPAA applies to their organization
  • Obtaining any required patient authorizations or consents
  • Configuring user permissions appropriately
  • Maintaining secure devices and networks
  • Workforce HIPAA training
  • Password management
  • Internal security policies
  • Responding to security incidents within their organization
  • Compliance with applicable healthcare laws, professional obligations, and regulatory requirements

Business Associate Agreement (BAA)

Where required by applicable law, Lextiff is prepared to enter into a separate Business Associate Agreement (BAA) with eligible Customers. The BAA establishes each party's responsibilities regarding the handling of Protected Health Information and supplements the Lextiff Terms of Service, Privacy Policy, and Data Processing Addendum.

Execution of a BAA does not, by itself, establish HIPAA compliance. Both Lextiff and the Customer remain responsible for fulfilling their respective obligations under applicable law.

Customers who require a Business Associate Agreement may contact our Privacy Team for additional information.

Request a BAA →

Incident Response

Lextiff maintains documented incident response procedures designed to:

  • Detect potential security events
  • Investigate reported incidents
  • Contain and mitigate confirmed security incidents
  • Restore affected systems
  • Notify affected Customers where required by applicable law or contractual obligations
  • Review and improve security controls following significant incidents

If Lextiff becomes aware of a confirmed security incident affecting Customer Data, we will respond in accordance with our contractual obligations, applicable law, and our documented incident response procedures.

Vendor Management

Lextiff works with carefully selected third-party service providers to support the operation of the Services.

Where applicable, vendors that process Customer Data are evaluated for their security, operational, and privacy practices and are required to maintain contractual obligations appropriate to the services they provide.

Additional information regarding our service providers is available in our Subprocessor List.

Privacy & Data Protection

Lextiff's privacy and security program is supported by a comprehensive set of policies and agreements, including:

Frequently Asked Questions

Contact Us

Questions regarding HIPAA, privacy, or Business Associate Agreements may be directed to:

Privacy Team

privacy@lextiff.com

Security Team

security@lextiff.com