Evaluation & Due Diligence
Evaluation & Due Diligence
Category: Customer Lifecycle | Audience: undefined | Page: 26 of 33
Table of Contents
- Sign a Business Associate Agreement (BAA)
Evaluation & Due Diligence
Welcome to the Evaluation & Due Diligence section of the Elixia Health clinical trial platform onboarding documentation. This section is designed to provide you with essential information and steps to ensure a thorough evaluation and due diligence process before engaging with our platform.
Key Concepts
Before diving into the specifics, it's important to understand a few key concepts:
- HIPAA Compliance: Ensures the protection of sensitive patient data.
- Business Associate Agreement (BAA): A legal contract that outlines the responsibilities of both parties in handling Protected Health Information (PHI).
- GDPR Compliance: Ensures the protection of personal data of individuals within the European Union.
- Data Encryption: Protects data both at rest and in transit to maintain security and integrity.
- WCAG Accessibility: Ensures that our platform is accessible to users with disabilities.
What You Can Do
- Evaluate the platform's compliance with HIPAA and GDPR.
- Sign a Business Associate Agreement (BAA).
- Ensure data is encrypted at rest and in transit.
- Verify WCAG accessibility compliance.
- Understand how PHI is stored versus referenced within the platform.
How To
Sign a Business Associate Agreement (BAA)
- Log in to the Elixia Health MTJ portal as an Admin or Project Ops user.
- Use your organizational credentials to access the portal.
- Ensure you have administrative privileges to sign agreements on behalf of your organization.
- Navigate to the "Agreements" section and click on "Business Associate Agreement".
- The Agreements section is typically found in the main navigation menu under Settings or Legal.
- Select the current version of the BAA to be signed.
- Review the BAA terms and conditions carefully, paying attention to:
- Data Protection Obligations: How PHI will be handled and protected.
- Permitted Uses and Disclosures: What uses of PHI are allowed under the agreement.
- Breach Notification: Procedures for reporting security breaches or unauthorized access.
- Term and Termination: Duration of the agreement and conditions for termination.
- Indemnification Clauses: Responsibility for data protection failures.
- Audit Rights: Elixia Health's right to audit compliance.
- If you agree to the terms, click "Sign" to electronically sign the agreement.
- Verify that your legal and compliance team have reviewed the document.
- Electronic signature is legally binding and will be timestamped.
- An email confirmation will be sent to the authorized signatory.
- Once signed, the BAA will be stored in the MTJ portal for your reference.
- Access the signed BAA anytime from the "Signed Agreements" section.
- Download a copy for your records and regulatory compliance files.
- The effective date of the BAA begins upon signature.
Verify Data Encryption
- Review the documentation on encryption methods for data at rest:
- Database-Level Encryption: All databases are encrypted using industry-standard algorithms (AES-256) to protect stored data.
- File-Level Encryption: Uploaded documents and media files are encrypted at the filesystem level to prevent unauthorized access.
- Column-Level Encryption: Sensitive columns containing PHI (e.g., patient identifiers, medical record numbers) are encrypted at the database column level.
- Verify that encryption keys are managed securely and rotated regularly according to security policies.
- Ensure that data in transit is encrypted using multiple security layers:
- TLS 1.3: All data transmitted between client and server is encrypted using TLS 1.3 (the latest version of the Transport Layer Security protocol).
- Secure API Gateways: All API communications are routed through secure gateways with authentication and encryption.
- VPN Tunnels: For sensitive operations, data may be transmitted through encrypted VPN tunnels for an additional layer of security.
- SFTP Protocols: File transfers use SFTP (SSH File Transfer Protocol) instead of standard FTP to ensure encrypted transmission.
- Verify that SSL/TLS certificates are valid and properly configured across all endpoints.
- Additional encryption verification steps:
- Request and review the Security and Encryption Documentation from your Elixia Health account manager.
- Verify that encryption algorithms meet HIPAA and GDPR requirements.
- Ensure that key management practices comply with security standards (NIST guidelines).
- Document encryption verification as part of your compliance audit trail.
Tips & Best Practices
- Regularly Review Compliance: Stay updated with the latest HIPAA and GDPR regulations to ensure ongoing compliance.
- Maintain Documentation: Keep all signed agreements and compliance documentation readily accessible for audits and reviews.
- Engage with Data Protection Teams: Collaborate with your Data Protection Officer (DPO) or equivalent to ensure all due diligence steps are thoroughly completed.
Next Steps
- Complete the BAA: Ensure your organization has signed the Business Associate Agreement.
- Review Encryption Practices: Verify that data encryption methods are implemented and maintained.
- Check Accessibility: Ensure the platform meets WCAG 2.1 standards for accessibility.
- Understand PHI Handling: Familiarize yourself with how PHI is stored and referenced within the platform.
By following these steps, you'll be well-prepared to engage with the Elixia Health clinical trial platform confidently and securely.
Navigation
← Previous: Patient Workflows & Flowchart
📚 Documentation HomeNext: Contracting & Compliance Validation →
Generated from MCT Knowledge Base • v1.1.0 • January 2, 2026