LNC Nexus · Trust Center← Back to LNC Nexus
Trust Center document

HIPAA Security Rule Mapping Overview

Public security and assurance reference

HIPAA Security Rule Mapping Overview

Status: Configuration and review reference

Scope

This public summary describes how LNC Nexus security capabilities can support a customer’s HIPAA Security Rule program. It is not a certification, attestation, legal opinion, or substitute for the customer’s risk analysis and implementation decisions.

Administrative Safeguards

LNC Nexus supports customer programs for:

Physical Safeguards

Physical safeguards are determined by the environment in which LNC Nexus is operated. Customers and hosting providers must address facility access, workstation security, devices, media, physical monitoring, and secure disposal appropriate to the deployment.

Technical Safeguards

LNC Nexus provides capabilities that support:

Exact thresholds, system identifiers, deployment topology, storage locations, and operational procedures are not published in this public document. They are verified as part of a private security review.

Customer Responsibilities

Customers must establish and document:

  1. A lawful basis for handling PHI and a minimum-necessary data policy
  2. Workforce authorization, training, and access lifecycle procedures
  3. Environment, endpoint, network, storage, key, backup, and retention safeguards
  4. Incident, breach-notification, legal-hold, and disaster-recovery procedures
  5. Required business associate and subcontractor agreements
  6. A current HIPAA risk analysis and periodic evaluation process

Assurance Boundary

LNC Nexus does not claim that a customer is HIPAA compliant merely because the application provides security features. Deployment-specific evidence, contractual terms, and control testing are handled through authenticated review channels.