HIPAA Compliance
Last updated: May 19, 2026
Laion Agency is committed to supporting our med spa clients in maintaining HIPAA compliance. While Laion is not itself a Covered Entity, we operate as a Business Associate when handling Protected Health Information (PHI) on behalf of clients.
1. Business Associate Agreement
All clients subject to HIPAA receive a Business Associate Agreement (BAA) signed before any access to systems containing PHI. The BAA outlines our obligations regarding the use, disclosure, and safeguarding of PHI under HIPAA rules.
2. Safeguards in Place
We implement administrative, physical, and technical safeguards including:
- End-to-end encryption for all data in transit and at rest
- Role-based access controls — only authorized personnel access client systems
- Annual HIPAA training for all team members handling client accounts
- Audit logs of all access to systems containing PHI
3. Vendor Selection
We only use HIPAA-compliant vendors for any service that may touch PHI. This includes our hosting provider (Vercel — BAA available), communication tools, and AI services. We never use non-compliant tools for client work involving PHI.
4. Breach Notification
In the unlikely event of a security breach involving PHI, we will notify affected clients within 24 hours of discovery and provide all information required for HIPAA breach notification obligations.
5. Contact
For HIPAA-related questions or to request a BAA:
Laion LLC — HIPAA Compliance Officer
contact@thelaion.com
Casper, Wyoming, USA