Healthcare information deserves deliberate protection.
Aayu handles practice, prescriber, patient, order, and payment information. Our role and safeguarding responsibilities are documented in a Business Associate Agreement with each practice.
A BAA before protected health information.
Aayu signs a Business Associate Agreement with each practice before protected health information is used in Aayu.
The agreement defines permitted uses and disclosures, safeguarding responsibilities, subcontractor obligations, incident responsibilities, and the handling of protected health information when the relationship ends.
HIPAA is not a software certification.
Compliance depends on contracts, technical controls, operating procedures, and the way each organization uses the system.
Focused infrastructure.
Aayu's application is hosted on Microsoft Azure. Payment processing is handled through Stripe.
These providers host Aayu's application and process its payments. Aayu remains responsible for configuring and operating its own systems appropriately.
Access with accountability.
Individual accounts
Authorized users receive individual credentials. Accounts should not be shared.
Role-based access
Permissions separate appropriate administrative workflows from prescriber-only actions.
Practice separation
Access controls are designed to prevent one practice from accessing another practice's patients or orders.
Activity records
Aayu records relevant activity associated with users, orders, and status changes.
Encryption
Information is encrypted in transit.
Security is a shared responsibility.
Practices are responsible for authorizing users, protecting credentials and devices, verifying recipients, removing access that is no longer needed, and reporting suspected unauthorized access promptly.
Affiliate pharmacies remain responsible for the systems and information they control.
If you believe you have identified a security issue or potential exposure of protected health information, contact support@aayuos.com.
Do not include patient information in ordinary email. Provide enough non-sensitive information for us to identify the issue and direct you to a secure reporting method.