HIPAA Compliance
Last updated: January 29, 2026
HIPAA Compliant Platform
InnovateMed Solutions is fully committed to HIPAA compliance. We implement comprehensive administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of Protected Health Information (PHI).
Encrypted Data
AES-256 at rest, TLS 1.3 in transit
AWS HIPAA Infrastructure
AWS Infrastructure
BAA Available
Business Associate Agreement for covered entities
Audit Logging
Complete access and activity tracking
How Your Data Is Processed
Understanding how your patient data moves through our system is essential for HIPAA compliance. Here's a transparent overview of our data processing workflow:
Audio Recording
You record the patient encounter in your browser. Audio is captured locally and encrypted before transmission.
Secure Storage
Audio files are temporarily stored in AWS S3 (HIPAA-eligible) with server-side encryption while awaiting processing.
Speech-to-Text Transcription
Audio is transcribed using OpenAI Whisper API. For files over 23MB, AWS Transcribe is used as a fallback.
AI Documentation Generation
The transcript is processed by OpenAI GPT-4 to generate the HPI, ICD-10 codes, and care plans based on your selected template.
Documentation Storage
Generated documentation is stored in AWS DynamoDB with encryption. You can access, edit, export, or delete at any time.
Important: Original audio files are retained for 30 days to allow for re-processing if needed, then automatically deleted. You can request immediate deletion at any time.
Our HIPAA Commitment
As a healthcare technology provider that processes Protected Health Information (PHI), InnovateMed Solutions operates as a Business Associate under HIPAA. We take this responsibility seriously and have implemented a comprehensive compliance program that includes:
- Designated HIPAA Privacy and Security Officers
- Comprehensive policies and procedures
- Regular workforce training
- Ongoing risk assessments
- Incident response procedures
- Business Associate Agreements with all subcontractors
Technical Safeguards
Encryption
- •Data at Rest: AES-256 encryption for all stored data in S3 and DynamoDB
- •Data in Transit: TLS 1.3 encryption for all communications
- •Audio Files: Encrypted during upload, processing, and temporary storage
Access Controls
- •Authentication: AWS Cognito with secure login and optional MFA
- •Authorization: Role-based access controls (RBAC) with team permissions
- •Session Management: Automatic timeout and secure logout
- •Unique User IDs: Individual accounts for all users
Audit Controls
- •Comprehensive audit logging of all access to PHI via AWS CloudWatch
- •Tamper-evident log storage in CloudWatch Logs
- •Regular log review and anomaly detection
- •6-year audit log retention per HIPAA requirements
Administrative Safeguards
Security Management
- •Annual risk analysis and management
- •Documented security policies and procedures
- •Regular security awareness training
- •Incident response and breach notification procedures
Workforce Security
- •Background checks for all employees with PHI access
- •Confidentiality agreements
- •Termination procedures for access revocation
- •Least-privilege access principles
Physical Safeguards
Our infrastructure is hosted on Amazon Web Services (AWS), which provides:
- •AWS data centers are fully compliant with global standards
- •24/7 physical security with biometric access
- •Environmental controls (fire suppression, climate control)
- •Redundant power and network connectivity
- •HIPAA-eligible services with signed BAA
Data Handling & Retention
Audio Recordings
- ✓ Encrypted during upload (TLS 1.3) and storage (AES-256)
- ✓ Transcribed by OpenAI Whisper API (with BAA) or AWS Transcribe for large files
- ✓ Retained for 30 days to allow re-processing, then auto-deleted
- ✓ You can request immediate deletion at any time
Generated Documentation
- ✓ Stored in AWS DynamoDB with AES-256 encryption
- ✓ Accessible only to you and authorized team members
- ✓ Retained until you delete or close your account
- ✓ Exportable in standard formats (PDF, FHIR R4)
Uploaded Documents (Labs, Imaging)
- ✓ Processed by OpenAI GPT-4 Vision for text extraction
- ✓ Stored temporarily during processing
- ✓ Extracted text incorporated into notes, originals not retained long-term
Subcontractors & Third-Party Services
We maintain Business Associate Agreements (BAAs) with all subcontractors who may process PHI:
Amazon Web Services (AWS)
Cloud infrastructure, storage (S3), database (DynamoDB), authentication (Cognito), and transcription (AWS Transcribe for large files)
✓ HIPAA BAA in place
OpenAI
Audio transcription (Whisper API), AI documentation generation (GPT-4), and document image analysis (GPT-4 Vision)
✓ HIPAA BAA in place (Enterprise tier)
Stripe
Payment processing only
Does not have access to PHI - payment data only
Business Associate Agreement (BAA)
BAA Available for Covered Entities
We provide Business Associate Agreements (BAAs) to all covered entities and their business associates. Our BAA outlines our responsibilities for protecting PHI and our commitment to HIPAA compliance.
To request a BAA, contact us at: compliance@innovatemed.ai
Breach Notification
Incident Response
In the unlikely event of a data breach involving PHI, we will notify affected covered entities within 60 days as required by HIPAA. We maintain documented incident response procedures and conduct regular breach response drills.
Your Rights & Controls
You maintain control over your patient data at all times:
- •Access: View all stored documentation anytime
- •Edit: Modify generated notes before finalizing
- •Export: Download documentation in PDF or FHIR R4 format
- •Delete: Request deletion of any or all records
- •Account Closure: Full data deletion upon account closure
Contact Our Compliance Team
For HIPAA-related questions, to request a BAA, or to report a concern:
InnovateMed Solutions
HIPAA Compliance Officer
Email: compliance@innovatemed.ai
General Support: michaelmartinez@innovatemedsolutions.com