Security & compliance

Last updated August 30, 2026

Most AI assistants were built for the open internet, with compliance added afterward. HIPAA Chat was built the other way around, for teams that handle protected health information (PHI), so the safeguards are the foundation rather than a setting. That shows up in four things a general-purpose chatbot cannot offer: a signed Business Associate Agreement with your organization, PHI that stays inside HIPAA-eligible cloud infrastructure, data that is never used to train AI models, and an assistant that is walled off from every other organization.

HIPAA and Business Associate Agreements

For any organization handling PHI, we operate under a Business Associate Agreement (BAA) with that organization, and HIPAA Chat is built to the HIPAA Security Rule. You can read the agreement itself on our BAA page.

HIPAA Chat is a tool for your work, not a medical record system, and AI answers should always be verified before they inform a care decision.

Your data stays in HIPAA-eligible cloud

HIPAA Chat runs entirely on HIPAA-eligible cloud infrastructure hosted in the United States. Your prompts and the documents you share are processed inside that boundary and are never sent to a consumer AI service.

Your data is never used to train AI models

Your messages, documents, and everything the assistant produces for you are not used to train AI models, ours or anyone else's. There is no advertising, no third-party analytics, and no sale of information, ever.

Encrypted in transit and at rest

All traffic to and from HIPAA Chat is encrypted in transit, and everything we store is encrypted at rest. Card payments are handled by a PCI-compliant payment provider; we never see or store card numbers.

Each organization is isolated

Every organization's conversations, files, and account data are fenced off from every other organization's, enforced at the data layer. One customer's workspace can never read another's.

The assistant is contained

The part of HIPAA Chat that reads your files and answers you is sandboxed: it can reach only what it needs to answer you, and it has no path to another organization's data. That is containment by design, not a trust assumption.

PHI stays out of logs and third parties

Our activity logs are metadata only: they never contain the text of your messages, your documents, or the AI's responses. Diagnostic monitoring is scrubbed of PHI before anything is recorded.

When an answer needs current information from the web, only the search text is sent out, never your identity, and the assistant is instructed to keep resident, client, and staff identifiers out of those queries.

Access is controlled by your organization

There is no self-signup. Accounts are created and removed by your organization's administrator, and when someone is removed, their access is revoked immediately.

Automatic logoff

HIPAA Chat signs you out automatically after a period of inactivity, so an unattended screen does not leave PHI exposed.

Your memory is private, and you can delete it

Anything the assistant remembers to be more helpful to you is private to you, and you can delete your history at any time from Settings. Uploaded and generated files are deleted automatically 90 days after upload, conversations persist until you delete them, and you can delete your account and everything associated with it from the account deletion page (completed within 30 days).

Built on certified infrastructure

HIPAA Chat runs on independently audited infrastructure certified under SOC 1/2/3, ISO 27001, and HITRUST, operated under a signed BAA. For a security review, we provide our BAA, the controls documented on this page, and full answers to your security and diligence questionnaires. Reach us through support and we will walk your team through whatever they need.