HIPAA Compliant GPT

Security · Compliance

Security your compliance team can sign off on.

This was built for clinical data from the first line of code. Here's how we protect what you type, what a model sees, and what ends up in your notes. Where a claim below isn't backed by a public source yet, the ledger further down marks it pending instead of implying it.

01

PHI tokenized before it reaches a model

Identifying details are detected and tokenized before anything leaves your session. The underlying model never sees a name, a date of birth, or a chart number in the clear.

02

Encrypted end to end

Data is encrypted in transit (TLS) and at rest. Your sessions and drafts are protected the whole way, not just while they're moving.

03

HIPAA compliant, BAA included

This is built for HIPAA compliance, and a signed Business Associate Agreement is included by default on every paid plan, not sold as a separate add-on. Free trial usage isn't covered. See the BAA page for exactly where that line sits.

04

Least-privilege access

Role-based access and authentication on every session. Only you reach your patients' information.

05

Never used for training

We collect the minimum needed to help you draft. We don't sell data, and clinical content is never used to train AI models, ours or any third party's.

06

Audited infrastructure

Runs on hardened cloud infrastructure with continuous monitoring and automated backups.

07

Logging & monitoring

Access to clinical data is logged and monitored for anomalies, so nothing happens in the dark.

08

Incident response

A documented incident response plan with breach notification aligned to HIPAA timelines.

Evidence ledger

Agreements & certifications

What's contractually in place versus what's on the roadmap.

EvidenceProduct & legal (PROJECT_CONTEXT §4)

BAAs ship on paid plans, not as a separate add-on. Self-serve trial usage is not covered. See the BAA page for exactly where that line sits.

EvidenceRoadmap item

Not complete yet. We're not going to claim it until an auditor has signed off.

EvidenceRoadmap item

Same as SOC 2 Type II, tracked internally, not yet closed, not claimed here.

Evidence ledger

Access & storage

The specifics a practice's compliance officer will usually ask for directly, beyond what's covered above.

EvidenceNot yet published

The product supports multi-model access, but we haven't confirmed a public list of which model providers are in rotation, or how that choice is made per request.

EvidenceProduct (Aug 2026)

By default, session data is kept for a limited period on every plan. You can set retention to zero to disable it entirely, or choose unlimited retention on higher plans.

EvidenceNot yet published

We haven't published a kept-current list of every vendor involved in delivering the service. That's an open item, not a secret.

Evidence ledger

Open items we're not hiding

Things this site intentionally does not claim, because they aren't true yet.

EvidenceProduct roadmap (PROJECT_CONTEXT §4)

Organizations that require government-cloud isolation aren't a current fit. We'd rather say that plainly than leave it ambiguous.

EvidenceProduct roadmap (PROJECT_CONTEXT §4)

The current focus is independent practices and small groups. Deep EHR write-back is not part of that today.

Ledger reviewedContent and product, Aug 2026, legal sign-off pending