Skip to content
ATTENDINGAI
Enhancing — never replacing — clinical expertise
← Back to home

Security & Compliance

HIPAA Compliance

Last updated: June 10, 2026

HIPAA-compliant. Encrypted. Audited. This page explains in plain language how ATTENDING AI handles Protected Health Information (PHI) — the safeguards we build into COMPASS and the provider portal, the agreements we sign with clinics, and what patients should know about how their information is protected.

How we approach HIPAA

ATTENDING AI was designed by a practicing family physician, so HIPAA is not an afterthought bolted onto the product — it is the operating assumption behind every feature. Four safeguards anchor our approach:

Encryption everywhere

PHI is encrypted in transit (TLS 1.2 or higher on every connection) and at rest (AES-256) in Microsoft Azure. No PHI travels or sits unencrypted.

Role-based access

Access follows clinical roles. A provider sees their clinic's patients; no one sees more than their role requires. PHI is masked in system logs.

Audit logging

Every access to PHI is recorded — user, timestamp, and clinical context — producing a complete audit trail retained to HIPAA documentation standards.

Minimum necessary

We collect and disclose only what is needed to prepare a patient's visit. Assessments started through a clinic link go to that clinic, and only that clinic.

These controls are backed by a written information security program — security policies, risk assessment, incident response, backup and recovery, and vendor management — owned by our founder and reviewed on a defined schedule.

Business Associate Agreements

When a clinic, health system, or other HIPAA covered entity uses COMPASS, ATTENDING AI acts as a business associate under HIPAA. We sign a Business Associate Agreement (BAA) with every covered-entity client before any PHI is exchanged. The BAA commits us in writing to the safeguards on this page — permitted uses, security controls, breach notification, and the handling of PHI at termination.

Requesting a BAA: reach us through the contact section on our home page and mention "BAA request." We will respond with the agreement and a short onboarding checklist.

Our infrastructure: Microsoft Azure

COMPASS runs on Microsoft Azure using HIPAA-eligible services, and Microsoft acts as our infrastructure business associate: HIPAA obligations are covered under Microsoft's standard BAA terms for Azure services, configured per Microsoft's HIPAA implementation guidance. AI processing (the summarization of text and analysis of optional photos) runs on Azure OpenAI within that same Azure environment — and no patient data is used to train AI models, ours or anyone else's.

What patients should know

  • Your clinic remains in charge of your record. Under HIPAA, your clinic is the "covered entity"; ATTENDING AI processes your information on its behalf, under a signed BAA. Your clinic's Notice of Privacy Practices also applies to you.
  • You are told where your answers go before you share them. When you start an assessment through a clinic link, the app states it plainly:

"Your responses will be shared with your clinic to prepare for your visit."

  • Your information is used to prepare your visit — nothing else. No sale of personal data, no advertising use, no model training. See our Privacy Policy for the full picture, including your access, correction, and deletion rights.
  • Photos are optional. If you upload one, it is encrypted and handled with the same safeguards as the rest of your assessment.

Breach notification

We maintain a written incident response plan with a designated privacy and security officer. If a breach of unsecured PHI occurs, we will notify affected covered-entity clients without unreasonable delay, consistent with the HIPAA Breach Notification Rule (45 CFR 164.400–414) and the timelines in each client's BAA, and we will support the clinic's notifications to affected patients. We treat transparency after an incident as non-negotiable.

An honest note on certifications

HIPAA has no official "certification," and we will not pretend otherwise. What we offer instead is concrete: the safeguards described on this page, a signed BAA with every covered-entity client, infrastructure on HIPAA-eligible Azure services under Microsoft's BAA, and audit trails that show our controls working. As independent third-party assessments are completed, we will say so here — and not before.

Informational only. This page describes our practices in plain language for patients and clinics. It is not legal advice, and it does not replace the terms of a signed Business Associate Agreement. Covered entities should consult their own counsel on HIPAA obligations.

Questions

For HIPAA, security, or BAA questions, use the contact section on our home page — it reaches us directly.

© 2026 ATTENDING AI LLC. All rights reserved.  |  Last updated: June 10, 2026
  • Home
  • Privacy
  • Terms
  • HIPAA