HIPAA Compliance
Aimform supports HIPAA compliance for organizations that handle Protected Health Information (PHI).
1. Business Associate Agreement
A BAA is required before processing PHI. To accept the BAA: sign in, navigate to Workspace Settings → Compliance, enable HIPAA Mode, and click Accept BAA. The agreement is effective immediately.
2. BAA Coverage
- Permitted uses and disclosures of PHI (45 CFR §164.502)
- Administrative, physical, and technical safeguards (§164.308–312)
- Breach notification within 60 calendar days (§164.410)
- Subcontractor PHI obligations
- Access, amendment, and accounting of disclosures (§164.524–528)
- PHI return or destruction on termination
3. Technical Safeguards
- Encryption at rest: D1 and R2 (Cloudflare, FIPS 140-2)
- Encryption in transit: TLS 1.3
- Access controls: role-based with per-organization data isolation
- Audit controls: all data access logged (§164.312(b))
- Authentication: multi-factor-capable, JWT-based sessions
4. AI Inference Routing
For HIPAA-enabled organizations, all AI inference is automatically routed through AWS Bedrock (HIPAA-eligible). Non-HIPAA organizations use DeepSeek by default. This routing is transparent.
5. Subcontractors
| Provider | Service | PHI Access | HIPAA Status |
|---|---|---|---|
| Cloudflare | Infrastructure (D1, R2, Workers) | Yes | SOC 2 Type II, ISO 27001 |
| AWS Bedrock | AI inference (HIPAA orgs) | Yes | HIPAA-eligible, signs BAA |
| Stripe | Payment processing | No | SOC 2 |
| DeepSeek | AI (non-HIPAA orgs) | No | Not used for PHI |
6. Audit Logging
Comprehensive audit log per HIPAA §164.312(b). Each entry: organization ID, user profile, resource, action, IP address, user agent, timestamp. Available in Workspace Settings → Compliance.
7. Breach Notification
In the event of a breach of unsecured PHI, Aimform notifies the Covered Entity without unreasonable delay and within 60 calendar days of discovery (§164.410).
8. Covered Entity Responsibility
Aimform provides HIPAA-eligible infrastructure. The Covered Entity is responsible for its own compliance including workspace configuration, access controls, and workforce PHI training.
9. Contact
Security Officer: [email protected] · Privacy Officer: [email protected]