Back to Home

HIPAA Compliance

Last updated: January 29, 2026

HIPAA Compliant Platform

InnovateMed Solutions is fully committed to HIPAA compliance. We implement comprehensive administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of Protected Health Information (PHI).

Encrypted Data

AES-256 at rest, TLS 1.3 in transit

AWS HIPAA Infrastructure

AWS Infrastructure

BAA Available

Business Associate Agreement for covered entities

Audit Logging

Complete access and activity tracking

How Your Data Is Processed

Understanding how your patient data moves through our system is essential for HIPAA compliance. Here's a transparent overview of our data processing workflow:

1

Audio Recording

You record the patient encounter in your browser. Audio is captured locally and encrypted before transmission.

TLS 1.3 encryption during upload
2

Secure Storage

Audio files are temporarily stored in AWS S3 (HIPAA-eligible) with server-side encryption while awaiting processing.

AES-256 encryption at rest
3

Speech-to-Text Transcription

Audio is transcribed using OpenAI Whisper API. For files over 23MB, AWS Transcribe is used as a fallback.

OpenAI processes under their BAA; AWS Transcribe is HIPAA-eligible
4

AI Documentation Generation

The transcript is processed by OpenAI GPT-4 to generate the HPI, ICD-10 codes, and care plans based on your selected template.

OpenAI Enterprise with BAA covers PHI processing
5

Documentation Storage

Generated documentation is stored in AWS DynamoDB with encryption. You can access, edit, export, or delete at any time.

AES-256 encryption; user-controlled retention

Important: Original audio files are retained for 30 days to allow for re-processing if needed, then automatically deleted. You can request immediate deletion at any time.

Our HIPAA Commitment

As a healthcare technology provider that processes Protected Health Information (PHI), InnovateMed Solutions operates as a Business Associate under HIPAA. We take this responsibility seriously and have implemented a comprehensive compliance program that includes:

  • Designated HIPAA Privacy and Security Officers
  • Comprehensive policies and procedures
  • Regular workforce training
  • Ongoing risk assessments
  • Incident response procedures
  • Business Associate Agreements with all subcontractors

Technical Safeguards

Encryption

  • Data at Rest: AES-256 encryption for all stored data in S3 and DynamoDB
  • Data in Transit: TLS 1.3 encryption for all communications
  • Audio Files: Encrypted during upload, processing, and temporary storage

Access Controls

  • Authentication: AWS Cognito with secure login and optional MFA
  • Authorization: Role-based access controls (RBAC) with team permissions
  • Session Management: Automatic timeout and secure logout
  • Unique User IDs: Individual accounts for all users

Audit Controls

  • Comprehensive audit logging of all access to PHI via AWS CloudWatch
  • Tamper-evident log storage in CloudWatch Logs
  • Regular log review and anomaly detection
  • 6-year audit log retention per HIPAA requirements

Administrative Safeguards

Security Management

  • Annual risk analysis and management
  • Documented security policies and procedures
  • Regular security awareness training
  • Incident response and breach notification procedures

Workforce Security

  • Background checks for all employees with PHI access
  • Confidentiality agreements
  • Termination procedures for access revocation
  • Least-privilege access principles

Physical Safeguards

Our infrastructure is hosted on Amazon Web Services (AWS), which provides:

  • AWS data centers are fully compliant with global standards
  • 24/7 physical security with biometric access
  • Environmental controls (fire suppression, climate control)
  • Redundant power and network connectivity
  • HIPAA-eligible services with signed BAA

Data Handling & Retention

Audio Recordings

  • ✓ Encrypted during upload (TLS 1.3) and storage (AES-256)
  • ✓ Transcribed by OpenAI Whisper API (with BAA) or AWS Transcribe for large files
  • ✓ Retained for 30 days to allow re-processing, then auto-deleted
  • ✓ You can request immediate deletion at any time

Generated Documentation

  • ✓ Stored in AWS DynamoDB with AES-256 encryption
  • ✓ Accessible only to you and authorized team members
  • ✓ Retained until you delete or close your account
  • ✓ Exportable in standard formats (PDF, FHIR R4)

Uploaded Documents (Labs, Imaging)

  • ✓ Processed by OpenAI GPT-4 Vision for text extraction
  • ✓ Stored temporarily during processing
  • ✓ Extracted text incorporated into notes, originals not retained long-term

Subcontractors & Third-Party Services

We maintain Business Associate Agreements (BAAs) with all subcontractors who may process PHI:

  • Amazon Web Services (AWS)

    Cloud infrastructure, storage (S3), database (DynamoDB), authentication (Cognito), and transcription (AWS Transcribe for large files)

    ✓ HIPAA BAA in place

  • OpenAI

    Audio transcription (Whisper API), AI documentation generation (GPT-4), and document image analysis (GPT-4 Vision)

    ✓ HIPAA BAA in place (Enterprise tier)

  • Stripe

    Payment processing only

    Does not have access to PHI - payment data only

Business Associate Agreement (BAA)

BAA Available for Covered Entities

We provide Business Associate Agreements (BAAs) to all covered entities and their business associates. Our BAA outlines our responsibilities for protecting PHI and our commitment to HIPAA compliance.

To request a BAA, contact us at: compliance@innovatemed.ai

Breach Notification

Incident Response

In the unlikely event of a data breach involving PHI, we will notify affected covered entities within 60 days as required by HIPAA. We maintain documented incident response procedures and conduct regular breach response drills.

Your Rights & Controls

You maintain control over your patient data at all times:

  • Access: View all stored documentation anytime
  • Edit: Modify generated notes before finalizing
  • Export: Download documentation in PDF or FHIR R4 format
  • Delete: Request deletion of any or all records
  • Account Closure: Full data deletion upon account closure

Contact Our Compliance Team

For HIPAA-related questions, to request a BAA, or to report a concern:

InnovateMed Solutions

HIPAA Compliance Officer

Email: compliance@innovatemed.ai

General Support: michaelmartinez@innovatemedsolutions.com