Last updated: August 23, 2026
When HIPAA applies
When Leyoxa creates, receives, maintains, or transmits Protected Health Information on behalf of a US covered entity, the parties determine Leyoxa’s role, the permitted workflow, and whether a Business Associate Agreement is required before PHI processing begins.
Implementation review
Each PHI workflow is reviewed for data categories, sources, users, vendors, subprocessors, storage and transit paths, access requirements, retention, auditability, patient-facing behavior, and incident responsibilities. Features that cannot be delivered within the approved boundary are not enabled.
Safeguard areas
- unique identity, role and location access, least privilege, and access review;
- encryption in transit and at rest where PHI is processed or stored;
- audit logging and monitoring appropriate to the workflow;
- minimum-necessary data use and documented retention;
- backup, recovery, incident response, and breach-notification coordination;
- written obligations for subprocessors that handle PHI;
- human review and escalation for consequential or uncertain actions.
Shared responsibility
The dental organization remains responsible for its workforce, patient authorizations, notices, source-system configuration, endpoint security, account administration, and lawful instructions. Leyoxa is responsible for the safeguards and obligations assigned to it in the governing service agreement and BAA. Infrastructure and integration vendors retain their own defined responsibilities.
Canada
Canadian implementations are assessed separately against applicable federal and provincial privacy requirements, contractual roles, and the systems involved. A US HIPAA design does not automatically satisfy Canadian obligations.
No blanket certification claim
This page describes Leyoxa’s approach. It is not a certification, legal opinion, or substitute for the signed agreements and implementation documentation governing a customer deployment.
Questions: contact@leyoxa.com