Designed for protected health information
Our safeguards and commitments to the practices and patients we serve.
Safeguards
Encryption
AES-256 at rest using customer-managed keys and TLS 1.3 in transit.
Access control
Multi-factor authentication and role-based access control.
Audit logs
Every agent action and handoff is recorded.
Business associate agreements
Signed with each covered-entity customer and flowed down to infrastructure providers.
AI data handling
Generative AI processing runs with data-use opt-out and zero-data-retention settings. No PHI is used to train public or commercial foundation models.
Secure disposal
Return or destruction of PHI at termination following NIST SP 800-88 guidance.
Digital twin ethics
Consent. A twin is created only from a person who has given written consent, and consent can be withdrawn.
Disclosure. Patients are told when they are interacting with AI and video twins are labeled AI-generated.
Oversight. Scripts and rules are approved by the practice and anything uncertain is escalated to a human.
To report a security concern or request our security documentation, contact us.