Trust · 8 min

“HIPAA compliant” is not a useful product shortcut.

A records review is a shared operating responsibility defined by purpose, people, access, vendors, retention, contracts, and evidence.

Leyoxa Care Ledger is a product direction pending proof. Security and contractual requirements are evaluated for the signed review scope rather than claimed as a blanket property.

Define the purpose before the data

The practice should approve the question, location, record types, date range, people, and outputs before access. “All data because it may help” is not a defensible scope.

Use the minimum necessary records

Read-only does not mean risk-free. Limit fields, identities, environments, and duration to the approved review. Do not place patient data in email or scheduling forms.

Put responsibilities in writing

The practice and vendor need clear roles for permitted use, safeguards, subprocessors, incident notification, return or destruction, and termination. Where Leyoxa acts as a business associate, the applicable BAA process belongs in the engagement.

Preserve provenance and audit

Every ledger item should retain its source. Consequential access, review, export, and disposition should be attributable to a named identity. Shared credentials defeat that evidence.

Separate reconciliation from clinical authority

Leyoxa does not assert a diagnosis and does not write to the PMS in the current product. A dentist reviews the evidence and records any clinical decision in the authoritative system.

Close the review deliberately

Before the work begins, define retention, deletion, export, access revocation, and who verifies completion. The controls should match the actual architecture and signed scope.

Review Leyoxa’s Trust Center, Privacy notice, HIPAA approach, and BAA process.

Scope trust with the review.

Open the Trust Center