HIPAA Compliance

Aimform supports HIPAA compliance for organizations that handle Protected Health Information (PHI).

1. Business Associate Agreement

A BAA is required before processing PHI. To accept the BAA: sign in, navigate to Workspace Settings → Compliance, enable HIPAA Mode, and click Accept BAA. The agreement is effective immediately.

2. BAA Coverage

  • Permitted uses and disclosures of PHI (45 CFR §164.502)
  • Administrative, physical, and technical safeguards (§164.308–312)
  • Breach notification within 60 calendar days (§164.410)
  • Subcontractor PHI obligations
  • Access, amendment, and accounting of disclosures (§164.524–528)
  • PHI return or destruction on termination

3. Technical Safeguards

  • Encryption at rest: D1 and R2 (Cloudflare, FIPS 140-2)
  • Encryption in transit: TLS 1.3
  • Access controls: role-based with per-organization data isolation
  • Audit controls: all data access logged (§164.312(b))
  • Authentication: multi-factor-capable, JWT-based sessions

4. AI Inference Routing

For HIPAA-enabled organizations, all AI inference is automatically routed through AWS Bedrock (HIPAA-eligible). Non-HIPAA organizations use DeepSeek by default. This routing is transparent.

5. Subcontractors

ProviderServicePHI AccessHIPAA Status
CloudflareInfrastructure (D1, R2, Workers)YesSOC 2 Type II, ISO 27001
AWS BedrockAI inference (HIPAA orgs)YesHIPAA-eligible, signs BAA
StripePayment processingNoSOC 2
DeepSeekAI (non-HIPAA orgs)NoNot used for PHI

6. Audit Logging

Comprehensive audit log per HIPAA §164.312(b). Each entry: organization ID, user profile, resource, action, IP address, user agent, timestamp. Available in Workspace Settings → Compliance.

7. Breach Notification

In the event of a breach of unsecured PHI, Aimform notifies the Covered Entity without unreasonable delay and within 60 calendar days of discovery (§164.410).

8. Covered Entity Responsibility

Aimform provides HIPAA-eligible infrastructure. The Covered Entity is responsible for its own compliance including workspace configuration, access controls, and workforce PHI training.

9. Contact

Security Officer: [email protected] · Privacy Officer: [email protected]