HarnessHealth

Where we stand on HIPAA.

Complete compliance matrix. What is live today and what is in process. The honest accounting is a governance signal.

HIPAA RequirementHow HarnessHealth addresses itStatus
BAA with covered entitiesOffered to qualifying covered-entity partners; none executed yetOn request
PHI encryption at restSupabase AES-256 encryptionLive
PHI encryption in transitTLS 1.3 via Vercel (SOC 2 Type II)Live
Access controlsRow-level security in Supabase; policies audited September 2026Live
Audit loggingEvery attestation event logged with NPI, timestamp, and document hashLive
No PHI in AI trainingNo PHI is sent to any model provider; API calls carry no persistent retentionLive
Minimum necessary standardRole-based access on the review path; remaining public read paths being closedIn progress
Business Associate statusWould operate as a Business Associate under an executed BAA; none executed yetPending first BAA
Breach notification60-day notification per HIPAA Rule; policy documentedPolicy available
SSO architectureOne Supabase identity across 45+ ecosystem sites; no PHI fragmentationLive
FHIR R4-aligned outputStandards-aligned connectors; Redox loop live on SurgeonValue, SDK not yet releasedPartial
Flat per-review physician feeSame fee whether the physician signs or declines; never a percentage, never tied to referralsPolicy
Formal Security Risk AssessmentIn processIn process
Penetration test reportIn scheduleIn process

Request a BAA

Business Associate Agreements are offered to qualifying covered-entity partners; none has been executed yet. Submit your request via the health systems evaluation form.

Request a BAA