HIPAA Compliance
NyxPulse is built for healthcare training workflows. Current self-serve accounts are designed for learner identity, enrollment, and course progress — not for storing clinical PHI by default.
Transport Security
Application traffic uses TLS in production via our hosting and auth providers.
Access Controls
Account authentication is handled by Firebase Auth with signed-in access to learner dashboards.
Business Associate Agreement
We can discuss and execute a BAA for covered-entity deployments that require one.
Incident Response
Security and privacy inquiries are routed to our compliance contacts for investigation.
Overview
NyxPulse supports healthcare organizations that need emergency and safety training. If your deployment will process Protected Health Information (PHI), contact us before go-live so we can review scope, execute a Business Associate Agreement when required, and confirm the appropriate safeguards for that engagement.
What the platform stores today
- Account identity and authentication data (via Firebase Auth)
- Course enrollment and completion status
- Learner progress checklists for enrolled courses
- Payment metadata required for Stripe checkout and receipts
- Contact/sales inquiry details you submit voluntarily
Please do not submit clinical notes, patient identifiers, or other PHI through contact forms or course content unless we have an active BAA and a confirmed PHI-capable configuration for your organization.
Business Associate Agreement (BAA)
Covered entities and business associates that need a BAA should contact us before processing PHI in NyxPulse. A BAA engagement typically covers permitted uses/disclosures, security obligations, breach notification, and subcontractor requirements.
To request a BAA discussion, email hipaa@nyxpulse.com.
Service providers
- Stripe — payment processing
- Firebase Authentication — sign-in and identity
- Vercel — application hosting
Contact
NyxCollective LLC
Privacy: privacy@nyxpulse.com
Security: security@nyxpulse.com
Phone: (623) 806-4918
