ForensicReport.org Built for HIPAA-compliant workflows

Security and posture

Built for HIPAA-compliant workflows

That phrase describes how the system is engineered. It is not a certification, and no such certification exists for HIPAA.

Where we actually are today

During early access the system runs on synthetic data only. No patient information is processed until the vendor agreements covering the production deployment are complete and the office has signed a Business Associate Agreement. We would rather say this plainly than let you assume otherwise.

Separated by office

Every record is scoped to the office that created it, enforced by policies inside the database itself. A mistake in the interface cannot expose another office's work, because the interface is not what is holding the line.

Encrypted storage, encrypted in both directions

Everything is encrypted on the way in, on the way out, and where it sits. Storage is managed cloud infrastructure with encryption at rest, not servers of our own in a room somewhere.

Access is controlled and recorded

Every account has a defined role, and what each person opened, changed, or exported is recorded in a log the application itself cannot edit or delete.

The AI is a scribe

It never interprets a case and never writes a conclusion. This is enforced in the design of every feature that touches report content, not left to a prompt.

Nothing leaves without you

The system does not transmit, file, or release a report anywhere. Export is an action you take, when you decide the draft is ready.

Built to be reviewed

Access control, audit behaviour, and data handling are covered by tests that run on every change, and the results are kept so your office can ask to see them.

What "built for HIPAA-compliant workflows" covers

  • A Business Associate Agreement with your office, signed before any patient data is processed
  • A BAA with every provider that touches that data, the AI provider included. No provider without one is used in production
  • Encryption in transit and at rest, in both directions
  • Access control by role, with records scoped to the office that created them
  • An append-only audit log the application cannot rewrite or delete
  • Minimum necessary handling, and no use of your data to train anything
  • Breach notification on a defined timeline
  • Workforce training and access review, with a named security contact

The full HIPAA statement  ·  Our Business Associate Agreement  ·  Sub-processors

Are you the security officer, or the one who has to approve this?

Buying software for a forensic office is rarely one person's decision. If you need to put this in front of a security officer, a privacy officer, or procurement, ask for the documentation set and send it on rather than writing the answers yourself.

  • How the system is built, in the terms a security review asks for
  • Our Business Associate Agreement
  • Which vendors process what, and under which agreements
  • Answers to the questionnaire your office already uses
  • Results of external testing, screening, and audits

Request the set

Tell us who is reviewing it and we will send what applies to your office.

Request documentation

Vendor-specific detail is sent on request rather than published, so that what you receive is current on the day you receive it.

Read the HIPAA statement →  ·  See our sub-processors →

Send us your security questionnaire

Offices that buy software like this usually have one. We would rather answer it early than late.

Contact us