Customer Lifecycle

Evaluation & Due Diligence

📄 26 of 33 📅 January 2, 2026 🏷️ v1.1.0

Evaluation & Due Diligence

Category: Customer Lifecycle | Audience: undefined | Page: 26 of 33

Table of Contents

- Sign a Business Associate Agreement (BAA)

- Verify Data Encryption


Evaluation & Due Diligence

Welcome to the Evaluation & Due Diligence section of the Elixia Health clinical trial platform onboarding documentation. This section is designed to provide you with essential information and steps to ensure a thorough evaluation and due diligence process before engaging with our platform.

Key Concepts

Before diving into the specifics, it's important to understand a few key concepts:

  • HIPAA Compliance: Ensures the protection of sensitive patient data.
  • Business Associate Agreement (BAA): A legal contract that outlines the responsibilities of both parties in handling Protected Health Information (PHI).
  • GDPR Compliance: Ensures the protection of personal data of individuals within the European Union.
  • Data Encryption: Protects data both at rest and in transit to maintain security and integrity.
  • WCAG Accessibility: Ensures that our platform is accessible to users with disabilities.

What You Can Do

  • Evaluate the platform's compliance with HIPAA and GDPR.
  • Sign a Business Associate Agreement (BAA).
  • Ensure data is encrypted at rest and in transit.
  • Verify WCAG accessibility compliance.
  • Understand how PHI is stored versus referenced within the platform.

How To

Sign a Business Associate Agreement (BAA)

  1. Log in to the Elixia Health MTJ portal as an Admin or Project Ops user.

- Use your organizational credentials to access the portal.

- Ensure you have administrative privileges to sign agreements on behalf of your organization.

  1. Navigate to the "Agreements" section and click on "Business Associate Agreement".

- The Agreements section is typically found in the main navigation menu under Settings or Legal.

- Select the current version of the BAA to be signed.

  1. Review the BAA terms and conditions carefully, paying attention to:

- Data Protection Obligations: How PHI will be handled and protected.

- Permitted Uses and Disclosures: What uses of PHI are allowed under the agreement.

- Breach Notification: Procedures for reporting security breaches or unauthorized access.

- Term and Termination: Duration of the agreement and conditions for termination.

- Indemnification Clauses: Responsibility for data protection failures.

- Audit Rights: Elixia Health's right to audit compliance.

  1. If you agree to the terms, click "Sign" to electronically sign the agreement.

- Verify that your legal and compliance team have reviewed the document.

- Electronic signature is legally binding and will be timestamped.

- An email confirmation will be sent to the authorized signatory.

  1. Once signed, the BAA will be stored in the MTJ portal for your reference.

- Access the signed BAA anytime from the "Signed Agreements" section.

- Download a copy for your records and regulatory compliance files.

- The effective date of the BAA begins upon signature.

Verify Data Encryption

  1. Review the documentation on encryption methods for data at rest:

- Database-Level Encryption: All databases are encrypted using industry-standard algorithms (AES-256) to protect stored data.

- File-Level Encryption: Uploaded documents and media files are encrypted at the filesystem level to prevent unauthorized access.

- Column-Level Encryption: Sensitive columns containing PHI (e.g., patient identifiers, medical record numbers) are encrypted at the database column level.

- Verify that encryption keys are managed securely and rotated regularly according to security policies.

  1. Ensure that data in transit is encrypted using multiple security layers:

- TLS 1.3: All data transmitted between client and server is encrypted using TLS 1.3 (the latest version of the Transport Layer Security protocol).

- Secure API Gateways: All API communications are routed through secure gateways with authentication and encryption.

- VPN Tunnels: For sensitive operations, data may be transmitted through encrypted VPN tunnels for an additional layer of security.

- SFTP Protocols: File transfers use SFTP (SSH File Transfer Protocol) instead of standard FTP to ensure encrypted transmission.

- Verify that SSL/TLS certificates are valid and properly configured across all endpoints.

  1. Additional encryption verification steps:

- Request and review the Security and Encryption Documentation from your Elixia Health account manager.

- Verify that encryption algorithms meet HIPAA and GDPR requirements.

- Ensure that key management practices comply with security standards (NIST guidelines).

- Document encryption verification as part of your compliance audit trail.

💡 Tip: Regularly review and update your encryption practices to align with the latest security standards and regulations.

Tips & Best Practices

  • Regularly Review Compliance: Stay updated with the latest HIPAA and GDPR regulations to ensure ongoing compliance.
  • Maintain Documentation: Keep all signed agreements and compliance documentation readily accessible for audits and reviews.
  • Engage with Data Protection Teams: Collaborate with your Data Protection Officer (DPO) or equivalent to ensure all due diligence steps are thoroughly completed.

Next Steps

  1. Complete the BAA: Ensure your organization has signed the Business Associate Agreement.
  2. Review Encryption Practices: Verify that data encryption methods are implemented and maintained.
  3. Check Accessibility: Ensure the platform meets WCAG 2.1 standards for accessibility.
  4. Understand PHI Handling: Familiarize yourself with how PHI is stored and referenced within the platform.

By following these steps, you'll be well-prepared to engage with the Elixia Health clinical trial platform confidently and securely.


← Previous: Patient Workflows & Flowchart

📚 Documentation Home

Next: Contracting & Compliance Validation


Generated from MCT Knowledge Base • v1.1.0 • January 2, 2026