How we handle your data, and our own
An honest description of the safeguards we build in, the lines we will not cross, and how this website itself is run. No badges, because there is no such thing as a HIPAA certification.
Six rules behind every build
PHI stays inside the boundary
We design around where PHI is, and move the work to the data rather than the data to the work.
Minimum necessary
Each person, account and process sees only what the job needs.
A person decides
AI proposes. People confirm, file and sign.
Deterministic before AI
If a rule, a lookup or a script solves it, we use that. Fewer models means fewer places for data to go.
Everything leaves a record
If it cannot be reconstructed afterward, it was not under control.
You are never locked in
It lives in your accounts or on hardware you control, and it is documented.
What we build in, mapped to the HIPAA Security Rule
This describes how we build; it is not a statement that your agency is compliant. Compliance is a determination for your covered entity.
| Safeguard | 45 CFR | What we put in place |
|---|---|---|
| Access control | 164.312(a) | Named accounts only, no shared logins. Group-based, least-privilege access with the reason for each grant written down. Guest accounts are governed and reviewed. Assistants are shared with named users, never “everyone”. |
| Authentication | 164.312(d) | Multi-factor sign-in through your identity provider. We never ask you to send us a password. |
| Audit controls | 164.312(b) | Every automated run writes to an append-only ledger: what went in (hashed), each step, what came out, who asked. Microsoft 365 audit logging is switched on and retained. |
| Integrity | 164.312(c) | We check that the output exists and is right, not that the script exited cleanly. Source documents are compared by hash. A person confirms before anything an AI read is filed. |
| Transmission security | 164.312(e) | Encrypted transport everywhere. Reports and notices stay inside your own mail domain; the system refuses to send them anywhere else. |
| Encryption at rest | 164.312(a)(2)(iv) | Patient and personnel documents live on encrypted volumes, with the keys bound to the machine so a reboot never means a passphrase written on a sticky note. Laptops that touch PHI are full-disk encrypted. |
| Physical safeguards | 164.310 | PHI-bearing hardware kept in controlled space, with defined handling for repair and disposal. |
| Risk analysis and management | 164.308(a)(1) | We supply the technical inputs: data-flow map, asset and vendor inventory, test evidence. Your compliance officer owns the analysis. |
| Workforce training | 164.308(a)(5) | Role-based training with an attendance and content record, delivered by us or alongside your own program. |
| Contingency planning | 164.308(a)(7) | Backups and a written restore procedure for everything we deploy, with a restore actually tested. |
| Vendor management | 164.308(b) | An inventory of sub-processors and which are covered by a Business Associate Agreement. New tools are added to it before they are used. |
| Ongoing evaluation | 164.308(a)(8) | A weekly self-test that checks every scheduled job really ran and its output really exists, so silence means success and not failure. |
| Documentation | 164.316 | Runbooks, SOPs and a change history for every system, written so a successor can run it. |
What we do not do
- Put PHI into a public AI tool, ever, for a demo or for convenience
- Send PHI by ordinary email or text message
- Keep shadow copies of your records on personal devices or unencrypted disks
- Touch PHI without a Business Associate Agreement in place
- Let an AI make an eligibility, billing or clinical decision with no person signing off
- Promise a certification, a guarantee against breach, or a legal outcome
If something goes wrong
We tell you promptly, preserve the logs, and help your compliance officer assess it. For California licensed agencies, the state has its own reporting rules for unlawful or unauthorized access to medical information, which we cover in training so the clock is never a surprise.
Held to the standard we describe
- No cookies, analytics or third-party scripts. We do not track visitors.
- Fonts are served from this site, not a font service, so your browser is not introduced to anyone else.
- A strict content security policy, HTTPS only, and the standard set of browser security headers.
- An automated test suite runs after every deploy and checks the headers, that sensitive files are not reachable, and that the contact form resists abuse.
- The contact form is the only place we collect anything: your name, email and message, relayed by email. See the privacy page.
Found a security problem on this site? Please tell us at hello@algorixtec.com. We will acknowledge it and fix it. Our security.txt has the details.