Skip to content
Legasus
NOTICE

HIPAA & Protected Health Information Notice

How Legasus supports firms that handle protected health information, including BAA availability and which configurations are HIPAA-eligible.

Last updated: Last updated April 1, 2026Version: Version 4Jurisdiction: Illinois, USAContact: privacy@legasus.ai

This is a public informational notice, not the Business Associate Agreement itself.

AIDAN LLC d/b/a Legasus provides legal-technology software that may be used by eligible customers to manage matters containing medical, treatment, billing, insurance, and other health-related information.

1. No “HIPAA Certification” Claim

HIPAA does not operate as a general product certification program under which software is simply labeled “HIPAA certified.”

Legasus's approach is to maintain applicable safeguards, designate which services/configurations are eligible for PHI, and enter into a Business Associate Agreement (“BAA”) where Legasus acts as a Business Associate and a BAA is required.

2. BAA Availability

Legasus can enter into a BAA with eligible Customers for Services and configurations that Legasus designates as HIPAA-eligible.

Customers that require a BAA should contact their Legasus account representative or privacy@legasus.ai before using Legasus to Process PHI where a BAA is required.

3. Not Every Feature Is Automatically HIPAA-Eligible

A Customer should not assume that every:

  • AI model;
  • Beta Feature;
  • preview feature;
  • Third-Party Service;
  • voice provider;
  • integration;
  • research provider;
  • API/MCP configuration; or
  • experimental function

is approved for PHI merely because Legasus offers a BAA for other Services.

Legasus may designate eligible and ineligible services based on technical safeguards, provider contracts, BAAs with downstream subprocessors, data flows, and compliance requirements.

4. PHI and Artificial Intelligence

For HIPAA-eligible AI functionality:

  • applicable PHI processing must occur through a configuration approved by Legasus for PHI;
  • required downstream Business Associate arrangements must be in place;
  • Customer Data is not used to train generalized/shared Legasus models for unrelated Customers; and
  • Customer remains responsible for determining that its use is appropriate and lawful.

Some Customers may request a Private AI Configuration. Private AI availability and HIPAA eligibility depend on the applicable Order Form and technical configuration.

5. Customer-Specific AI Learning

Where HIPAA-eligible and authorized, a Customer may use Customer-Specific AI Configuration to adapt its own isolated AI environment to firm-specific practices and materials.

Such Customer-specific learning is not used to improve another Customer's private agents or a generalized/shared model.

6. Security

Legasus maintains administrative, technical, and organizational safeguards described in the Legasus Security Addendum, including controls relating to:

  • encryption at rest and in transit;
  • MFA;
  • role-based access;
  • least privilege;
  • tenant isolation;
  • audit logging;
  • vulnerability management;
  • penetration testing;
  • secure development;
  • incident response;
  • backups;
  • business continuity/disaster recovery; and
  • vendor risk management.

For ePHI processed under an executed BAA, Legasus agrees to applicable HIPAA Security Rule obligations as described in the BAA.

7. Subprocessors

Legasus may use subprocessors to provide HIPAA-eligible Services only where Legasus determines the applicable subprocessor/service configuration is appropriate for PHI and required downstream agreements are in place.

The public Subprocessor List identifies providers generally used by Legasus. The presence of a provider on that list does not mean every service offered by that provider is HIPAA-eligible.

8. Customer Responsibilities

Customers remain responsible for their own HIPAA compliance, including:

  • determining whether they are a Covered Entity, Business Associate, or otherwise subject to HIPAA;
  • executing a BAA where required;
  • using only HIPAA-eligible features for PHI;
  • configuring users and permissions;
  • applying the Minimum Necessary standard;
  • determining what information may be disclosed;
  • securing Customer-managed devices and exports;
  • providing required notices and authorizations; and
  • complying with professional and legal obligations.

9. Legasus Is Not a Healthcare Provider

Legasus does not provide healthcare, diagnosis, treatment, medical advice, utilization review, medical necessity determinations, or insurance coverage advice.

Legasus processes health information as a technology provider when authorized by a Customer.

10. SOC 2

Legasus is currently undergoing a SOC 2 Type II examination. This does not mean a final SOC 2 Type II report has already been issued.

Once available, appropriate assurance materials may be shared with qualified Customers and prospects subject to confidentiality controls.

11. Request a BAA or Security Review

BAA / Privacy: privacy@legasus.ai
Security: security@legasus.ai
Legal: legal@legasus.ai