Legal
HIPAA statement
What we do, and what we do not claim, about HIPAA.
Placeholder, not a legal document yet
Structural outline only. One rule for the final text: this page describes how the system is built. It must never assert a certification, and it must not describe the production posture as achieved while the running stack is still uncovered.
Owner: Counsel, with the operator on technical facts
Our role
Business associate to the customer office, which remains the covered entity.
What "built for HIPAA-compliant workflows" means
Plain-language explanation that this describes engineering, not certification. No certification exists for HIPAA.
Administrative safeguards
Workforce training, access review, incident response, and the named security contact.
Technical safeguards
Access control, audit controls, integrity controls, transmission security, each mapped to what the system actually does.
Physical safeguards
Handled by the cloud provider; name the provider and its attestations.
Business Associate Agreements
The BAA we sign with customers, and the BAAs we hold with our own vendors.
Breach notification
The process and the timelines we commit to.
Current status
Honest statement of the early-access posture: synthetic data only until the covered production deployment is live.