NudgeWell is preparing an evidence-backed HIPAA-readiness baseline for customers whose approved, consented use case may involve sensitive health data. This page describes controls implemented in this repository and the legal, vendor, security, and operational prerequisites that still require owner evidence.
Who this applies to: This disclosure is relevant to healthcare organizations, health plans, healthcare clearinghouses, healthcare providers, and any employer who offers group health coverage subject to HIPAA and who uses NudgeWell's enterprise tier services.
Standard SMB tier: At the SMB tier (50–500 employees), NudgeWell does not collect, process, or store PHI. Our standard offering operates with benefits plan data only — wearable-derived categories are sensitive health data and are handled only through the documented opt-in controls. Enterprise customers requiring PHI handling can request a Business Associate Agreement (BAA) as described below.
PHI (Protected Health Information) includes any individually identifiable health information held or transmitted by a covered entity or its business associate, in any form (electronic, paper, oral).
PHI includes, but is not limited to:
EPHI (Electronic Protected Health Information) is PHI that is transmitted by or maintained in electronic media. NudgeWell's systems that handle EPHI (for customers with a signed BAA) are subject to the HIPAA Security Rule's requirements for administrative, physical, and technical safeguards.
For enterprise customers who execute a Business Associate Agreement, NudgeWell may receive, process, and transmit the following categories of PHI in connection with benefits engagement services:
| PHI Category | How We Use It |
|---|---|
| Health plan enrollment and eligibility data | To personalize benefits nudges, remind employees of available coverage, and track engagement with benefits programs |
| Claims data (anonymized or de-identified) | To identify gaps in preventive care, generate ROI analytics, and recommend appropriate benefits utilization |
| Provider information (NPI numbers, specialties) | To match employees with appropriate in-network providers and support the Benefits Coach provider finder |
| Utilization data (FSA/HSA balances, visit frequency) | To generate personalized nudges encouraging appropriate benefits usage and financial wellness |
We do not store: Full medical records, diagnosis histories, prescription data, or detailed treatment plans. PHI or sensitive wellness data is used only for the approved purpose and retention policy. The approved categories, retention period, deletion exceptions, and individual-rights workflow require legal/privacy confirmation for each customer and are not established by this page.
Under HIPAA, a Business Associate Agreement (BAA) is required when a covered entity discloses PHI to a third-party vendor who performs functions or activities on behalf of the covered entity that involve the use or disclosure of PHI.
NudgeWell offers BAAs to enterprise customers who require PHI handling as part of their benefits engagement program. Our BAA includes:
To initiate a BAA for your organization or learn more about our enterprise HIPAA readiness program, contact our team.
Request a BAANudgeWell implements administrative, physical, and technical safeguards appropriate to the sensitivity of EPHI in our systems.
hr_activity_logsNudgeWell maintains a breach-assessment and notification coordination runbook template. Legal and privacy owners must confirm the applicable rule, timelines, and customer-specific process before use.
Our timeline:
Breaches affecting fewer than 500 individuals are reported to HHS annually within 60 days of the end of the calendar year in which the breach occurred.
NudgeWell will coordinate individual-rights requests with the covered entity and privacy officer under the executed agreement and applicable law. The workflow, response timelines, and exceptions require owner/legal approval.
Requests should be directed to the covered entity or designated privacy contact. NudgeWell's repository contains deletion and access-review controls, but does not by itself establish a legal conclusion or complete an individual-rights request:
As a business associate, NudgeWell agrees to the following obligations under HIPAA:
Our BAA incorporates these obligations by reference and includes the minimum necessary standard, workforce sanctions, and amendment provisions required by 45 CFR Parts 160 and 164.
HIPAA is enforced by the Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Civil penalties for HIPAA violations range from $100 to $50,000 per violation, with a maximum of $1.5 million per violation category per year. Criminal penalties (for knowing or willful violations) can result in fines up to $250,000 per violation and imprisonment up to 10 years.
NudgeWell takes compliance seriously. This repository contains a readiness control baseline and operational runbook templates. Named owners must complete access reviews, risk reviews, incident exercises, backup/restore validation, workforce training, and vendor reviews before relying on those controls as operational evidence. NudgeWell has not completed an independent HIPAA readiness audit and does not display third-party compliance certifications.
For questions about this disclosure, to request a Business Associate Agreement, or to report a potential HIPAA concern:
NudgeWell Compliance Team
Email: hipaa@nudgewell.com
Enterprise inquiries: enterprise@nudgewell.com
If you believe your organization has experienced a HIPAA breach involving NudgeWell systems, please notify us immediately at hipaa@nudgewell.com so we can assist with your breach response process.
See also: Privacy Policy · Terms of Service