Security & HIPAA
Built for a regulated room.
Bring this page to your procurement meeting. Everything here is what we do today, nothing aspirational.
- HIPAA-compliant
- BAA before any PHI
- Encrypted in transit and at rest
- Audit-logged
- US data residency
- SOC 2 in progress
01
HIPAA-compliant by design
Every component of Aria is built to HIPAA requirements from day one, not bolted on afterwards. A Business Associate Agreement is signed before any PHI is processed.
02
Patient identity stays protected
Patient identity is separated from clinical content before it reaches any AI model. The model works with clinical context, not names, dates of birth or identifiers.
03
Encrypted in transit and at rest
TLS in transit, industry-standard encryption at rest. Credentials and secrets live in managed secret stores with automatic rotation.
04
Tamper-evident audit trail
Every read, write, escalation and clinical action is logged. Available to your compliance team on request.
05
Your data stays yours
Patient data is never used to train models. Data is isolated per practice; cross-tenant access is architecturally impossible. Portability to your own infrastructure is available.
06
Crisis and safety protocols
Documented escalation paths: clinician notification, emergency routing and safety overrides, testable and auditable by your clinical governance team.