HIPAA Notice

HIPAA practices, pilled honestly.

Pause-Health.ai is a prototype-in-the-open today: we are NOT yet a Business Associate to any Covered Entity, no BAA is in force, and the prototype handles no PHI. This page lays out the HIPAA framework the production stack is designed to operate under once design-partner provider organizations are onboarded, so a compliance reviewer can read the posture we are engineering toward without being misled about what is already in force.

Today vs. Designed

Two columns per HIPAA area. Today is the posture in the public prototype. Designed is the BA posture mapped against the HIPAA Privacy and Security Rules for the production stack pre-GA. See also /security for the broader technical-control view and /privacy for the patient-facing posture.

Business Associate status

TodayFuture

Pause-Health.ai is NOT a Business Associate today. No Covered Entity has executed a BAA with us, and we do not access, store, or transmit any patient PHI in the prototype.

DesignedPlanned

Once a provider organization (Covered Entity) executes a BAA, Pause-Health.ai will operate as their Business Associate for the menopause-triage workflows described in /proposal.

Business Associate Agreement (BAA)

TodayFuture

No BAA executed. The prototype runs on synthetic demo personas and seeded Salesforce sandbox records; nothing in scope of HIPAA flows through it.

DesignedPlanned

Standard HHS-aligned BAA executed with every Covered Entity before any PHI access. Includes breach-notification SLA (60-day max, 24-hour preliminary), sub-processor disclosure, and post-termination data return / destruction.

Permitted Uses & Disclosures

TodayFuture

Not applicable today (no PHI handled).

DesignedDesigned

PHI will be used only for the Permitted Uses defined in each BAA: typically treatment, payment, and healthcare operations as needed to deliver the menopause-triage service. Marketing / fundraising / sale uses are explicitly excluded.

Administrative safeguards

TodayDesigned

Security awareness, role-based access control design, sanction policy, and risk-analysis posture documented for the production stack. The prototype is run by a single founder and is not a multi-user environment yet.

DesignedPlanned

Full HIPAA Security Rule administrative safeguards — workforce training records, designated Security Officer, risk-management plan reviewed annually, sanction policy enforced.

Physical safeguards

TodayWired in prototype

Prototype runs on Vercel + Salesforce — both SOC 2 / ISO 27001 hosting environments with documented physical-access controls inherited at the platform layer.

DesignedPlanned

Same platform-layer inheritance plus device controls for any first-party endpoint that processes PHI (laptops with full-disk encryption, lost-device wipe, no production access from personal devices).

Technical safeguards

TodayWired in prototype

TLS 1.3 in transit (Vercel default), AES-256 at rest (Vercel + Salesforce defaults), OAuth Client Credentials for the live grounding path, OpenTelemetry-style trace spans for every Care Router decision.

DesignedDesigned

Same defaults plus SSO/MFA on every administrative surface, RBAC mapped to clinical roles, audit log retention aligned with HIPAA records requirements (6 years), and PHI redaction at the trace boundary before export to customer SIEM.

Breach notification

TodayFuture

No PHI to breach today. If a security incident affecting the prototype occurs we'll publish it transparently.

DesignedPlanned

Per BAA terms, Covered Entity notified within the BAA-specified SLA (24-hour preliminary in our template, full report within 60 days). Sub-processors flow notice upstream.

Patient rights

TodayFuture

No patient PHI is held today; rights of access / amendment / accounting of disclosures aren't yet in force because there's no protected record to exercise them against.

DesignedDesigned

Pause-Health.ai will support the Covered Entity in fulfilling patient rights of access, amendment, accounting of disclosures, and restriction requests via documented APIs and runbooks.

For privacy or compliance questions

Email privacy@pause-health.ai with privacy / HIPAA inquiries. We aim to respond within 2 business days; compliance reviews from prospective design partners get a faster path — flag the inquiry as such and we'll route accordingly. The BAA template is available on request.

Back to HomeSecurity & CompliancePrivacy