Where we stand on HIPAA.
Complete compliance matrix. What is live today and what is in process. The honest accounting is a governance signal.
| HIPAA Requirement | How HarnessHealth addresses it | Status |
|---|---|---|
| BAA with covered entities | Offered to qualifying covered-entity partners; none executed yet | On request |
| PHI encryption at rest | Supabase AES-256 encryption | Live |
| PHI encryption in transit | TLS 1.3 via Vercel (SOC 2 Type II) | Live |
| Access controls | Row-level security in Supabase; policies audited September 2026 | Live |
| Audit logging | Every attestation event logged with NPI, timestamp, and document hash | Live |
| No PHI in AI training | No PHI is sent to any model provider; API calls carry no persistent retention | Live |
| Minimum necessary standard | Role-based access on the review path; remaining public read paths being closed | In progress |
| Business Associate status | Would operate as a Business Associate under an executed BAA; none executed yet | Pending first BAA |
| Breach notification | 60-day notification per HIPAA Rule; policy documented | Policy available |
| SSO architecture | One Supabase identity across 45+ ecosystem sites; no PHI fragmentation | Live |
| FHIR R4-aligned output | Standards-aligned connectors; Redox loop live on SurgeonValue, SDK not yet released | Partial |
| Flat per-review physician fee | Same fee whether the physician signs or declines; never a percentage, never tied to referrals | Policy |
| Formal Security Risk Assessment | In process | In process |
| Penetration test report | In schedule | In process |
Request a BAA
Business Associate Agreements are offered to qualifying covered-entity partners; none has been executed yet. Submit your request via the health systems evaluation form.
Request a BAA