HIPAA Compliant GPT

Protocol release · Sourcing policy

How a claim earns a row on this site.

Every specific claim about HIPAA, PHI, BAAs, encryption, accuracy, or pricing on this site has to trace back to product or legal, or it doesn't get published. This page is the policy, not just the promise.

Document status

Owner
Product & legal
Human review required for
Privacy, consent, patient data
Unverified claims
Marked pending, not omitted silently
Last reviewed
Aug 2026

The policy

Three rules, applied consistently.

  1. A claim about HIPAA, BAA, PHI, encryption, accuracy, time saved, or pricing has to match what product and legal have confirmed, or it stays off the site.
  2. We don't invent experience, results, testimonials, or clinical outcomes to fill a gap. An empty or "pending" row is preferable to a fabricated one.
  3. Forbidden vocabulary, like "revolutionary," "magical," "replace doctors," or "best AI ever," doesn't appear here regardless of how well it might read.

Evidence ledger

Where the other ledgers live

This is a map, not a duplicate. Each row links to the page that carries the full detail.

EvidenceSee /security

The complete PHI-handling ledger, including what's confirmed and what's pending, lives on the security page.

EvidenceSee /privacy

Stage-by-stage breakdown of what happens to clinical content, plus what we haven't published yet on retention and subprocessors.

EvidenceSee /baa

What a BAA covers, what it doesn't, and how to request the current document.

EvidenceSee /use-cases

Each use-case page carries its own single-row ledger entry for the specific fit claim being made.