Compliance

The AI and health laws we follow.

For each law: what it asks, and how we meet it. The physician decides, with human oversight and a record that can be explained.

What it asks

Protect the privacy and security of patients' health information.

How we meet it

End-to-end encryption, two-factor access, an audit trail, scheduled destruction, and a BAA with every client.

What it asks

The health care professional must be able to independently review the basis for any recommendation.

How we meet it

Our AI only prepares. The physician reviews the basis, decides and signs, and every step is recorded and explainable.

HHS · Section 1557

45 CFR §92.210
What it asks

Covered entities must not discriminate through patient care decision support tools, and must identify and mitigate that risk.

How we meet it

Designed to support our clients' obligations: a transparent record of every step, and the physician makes every decision.

What it asks

Medical necessity decisions must rest on each enrollee's own medical history, physician recommendations and clinical notes.

How we meet it

Each assessment is prepared from the patient's own records, and nothing is submitted without the physician.

This page summarizes how we design our products around these laws. It is not legal advice; each client remains responsible for its own obligations.

Responsible AI

AI prepares. People decide.

Physician in control

Our AI only prepares; the physician reviews the basis, decides and signs — aligned with the FDA's criteria for non-device clinical decision support (21st Century Cures Act §3060; FD&C Act §520(o)(1)(E)).

Section 1557

Designed to support our clients' Section 1557 obligations on patient care decision support tools (45 CFR §92.210).

HIPAA

HIPAA-compliant by design · BAA with every client.

  • Live human oversightA person supervises the work as it happens.
  • TransparencyEvery step is recorded and can be explained.
  • No invented dataWhat can't be read with certainty goes to the physician.
  • Data protectionYour data is not used to train models.
  • Security reviewEvery file goes through a security review.

Compliance

HIPAA-compliant by design.

We sign a BAA with every client.

BAA: Business Associate Agreement.

  • End-to-end encryptionData travels sealed, there and back.
  • Two-factor access controlOnly the right people get in.
  • Audit trailEvery action is recorded and can't be altered.
  • Scheduled destructionData is destroyed on the agreed schedule.