Last updated: August 23, 2026
This page is not the agreement
This page explains availability and process. It does not create a Business Associate relationship, amend a service agreement, or replace a BAA signed by the parties.
When a BAA is considered
During workflow discovery, Leyoxa and the dental organization identify whether Leyoxa will create, receive, maintain, or transmit PHI on the organization’s behalf. If so, the parties define the covered services and execute the required agreement before production PHI is used.
What the agreement addresses
- permitted and required uses and disclosures of PHI;
- administrative, technical, and physical safeguard obligations;
- minimum-necessary use and access limitations;
- subcontractors that create, receive, maintain, or transmit PHI;
- security-incident and breach-notification responsibilities;
- support for access, amendment, and accounting obligations where applicable;
- return, destruction, or continued protection of PHI at termination;
- responsibilities retained by the covered entity.
Implementation documentation still matters
A BAA does not make every configuration appropriate. The technical design must still define identities, permissions, source systems, data flows, retention, audit, escalation, and vendor responsibilities for the selected workflow.
Request the BAA
Ask for the current Leyoxa BAA and security review as part of commercial and technical discovery. The executed agreement—not this page—governs the parties.