HarnessHealth

HIPAA compliance.

Complete compliance matrix. What is live today and what is in process. The honest accounting is a governance signal.

HIPAA RequirementHow HarnessHealth addresses itStatus
BAA with covered entitiesAvailable on requestAvailable
PHI encryption at restSupabase AES-256 encryptionLive
PHI encryption in transitTLS 1.3 via Railway (SOC 2 Type II)Live
Access controlsRow-level security in SupabaseLive
Audit loggingEvery attestation event logged with NPI, timestamp, and document hashLive
No PHI in AI trainingConfirmed — AI API calls include no persistent PHI retention by model providerLive
Minimum necessary standardRole-based data access enforced at API layerLive
Business Associate statusHarnessHealth operates as a Business Associate for covered entity partnersBAA available
Breach notification60-day notification per HIPAA Rule; policy documentedPolicy available
SSO architectureOne Supabase identity across all 45+ ecosystem sites; no PHI fragmentationLive
FHIR R4 compliant outputOpen source connectors, MIT licensedLive
OIG AO 25-03 alignmentFlat per-encounter fee structure, not percentage-basedLive
Formal Security Risk AssessmentIn processQ2 2026
Penetration test reportIn scheduleQ2 2026
FDA device registrationRequired for RTM billing via CPT 98975-98981In process

Request a BAA

Business Associate Agreements are available for covered entity partners. The BAA is available within 2 business days of a qualified request. Submit your request via the health systems evaluation form.

Request a BAA