Security & Compliance

Security built for healthcare workflows

EigenH AI is HIPAA compliant as a business associate — a BAA is signed before production PHI moves — and every security claim on this page points at the published Privacy Policy or Terms of Use it comes from.

System status report · Updated August 2026

Compliant

HIPAA Compliant

  • Business Associate Agreement
  • Encryption in transit and at rest
  • Access controls

STATUS: HIPAA_COMPLIANT

There is no certifying body for HIPAA and no product can be "HIPAA certified". Any vendor claiming that certification is describing something that does not exist. EigenH AI is HIPAA compliant as a business associate, and the signed BAA makes those obligations contractual.

Compliance status

HIPAA is where the work is. We publish what is in place today, plainly.

  • Compliant

    HIPAA Compliant

    EigenH AI is HIPAA compliant and operates as a business associate to the practice. A Business Associate Agreement is signed before production PHI is submitted, and the service runs on AWS.

    STATUS: HIPAA_COMPLIANT

  • Available

    Security review

    Security documentation is available to customers during procurement. The review covers the data a workflow needs, roles and permissions, tenant separation, recordings and integration access, retention, logging, and the vendors in the approved environment.

    STATUS: AVAILABLE

There is no certifying body for HIPAA and no product can be "HIPAA certified". Any vendor claiming that certification is describing something that does not exist. EigenH AI is HIPAA compliant as a business associate, and the signed BAA makes those obligations contractual.

Security posture at a glance

Each row states what our published Privacy Policy and Terms of Use support today. Program commitments are labeled as such, and nothing here claims a certification or third-party audit.

Published today
Business Associate Agreement

A Business Associate Agreement is signed before production PHI is submitted. EigenH AI approves the use case and environment in writing first, so the BAA is in effect before PHI moves — not after.

Terms of Use, HIPAA and BAAs
Published today
Encryption in transit and at rest

Customer data is encrypted in transit using TLS and encrypted at rest in production environments hosted on AWS. The specific standards that apply to an approved deployment are confirmed during the security review.

Privacy Policy, Security
Published today
Access controls

Accounts carry roles and permissions, and authentication and security events are recorded. Customers give each authorized user an individual account, assign appropriate roles, and remove access that is no longer needed.

Terms of Use, Accounts and Access
Published today
Data residency

The public website is hosted and delivered through AWS. Processing locations and any data-residency commitments for a customer deployment are defined in the applicable Customer Agreement or deployment documentation.

Privacy Policy, Processing Locations
Published today
Data retention

Information is retained as long as reasonably necessary to provide the services and meet legal, contractual, security, and accounting requirements. Retention periods for customer service data depend on the customer's configuration, the applicable agreement, and the type of data. We do not publish fixed periods.

Privacy Policy, Data Retention
Published today
Subprocessors and vendors

The production website stack is named in the Privacy Policy: Google Tag Manager, Google Analytics 4, PostHog, Apollo.io, RB2B, Calendly, Sentry, and AWS. Appearing on that list does not approve a vendor for PHI. A provider that would handle PHI or ePHI requires a Business Associate Agreement or equivalent flow-down terms.

Privacy Policy, Cookies and Analytics
Published today
AI model training

EigenH AI does not use customer PHI to train general-purpose or foundation AI models, does not sell patient data, and does not use PHI for advertising. AI vendor configurations are confirmed as part of vendor review.

Privacy Policy, AI-Enabled Processing
Program commitment
Audit logging

Authentication and security logs are among the technical information collected today, and logging and monitoring are stated design areas of the security program. The logging scope for a specific deployment is confirmed during the security review.

Privacy Policy, Security
Program commitment
Incident response

Incident response is a stated design area of the security program, and customers must notify EigenH AI of suspected unauthorized access. Notification duties and response commitments for a deployment are set in the applicable Customer Agreement or BAA. We do not publish a generic response-time guarantee.

Privacy Policy, Security

Rows labeled "Program commitment" describe stated design areas of the security program, not audited controls. We confirm current evidence, including logging scope, during a pre-production security review.

Last updated: August 7, 2026

HIPAA compliance

EigenH AI is HIPAA compliant and operates as a business associate to the practice. Approved workflows handle Protected Health Information and electronic Protected Health Information — PHI and ePHI — and a Business Associate Agreement is signed before production PHI moves.

HIPAA has no product certification and no certifying body, so we state the posture plainly instead of borrowing a badge: EigenH AI meets the HIPAA obligations that apply to it as a business associate, and the signed BAA makes those obligations contractual.

What has to be true before production PHI

Three things, all of them checkable:

  1. EigenH AI has approved the use case and production environment in writing. Approval is specific to a workflow and an environment, not a blanket account-level permission.
  2. A Business Associate Agreement is in effect. This is the “BAA Signed” status above — the agreement is executed before PHI moves, not after.
  3. The customer has completed the required security, access, consent, integration, and configuration steps. These are settled during the security review described below.

A customer’s use of EigenH AI does not make that customer compliant with HIPAA or any other law.

What EigenH AI is

EigenH AI, Inc. develops administrative workflow software for healthcare practices. EigenH AI is designed to help authorized teams manage patient calls, appointment requests, follow-up, staff tasks, and related front-desk work.

EigenH AI is not a healthcare provider, emergency service, medical device, or substitute for licensed clinical judgment.

Administrative AI boundaries

EigenH AI workflows must not:

  • Diagnose a medical or dental condition
  • Recommend treatment or medication
  • Provide emergency medical triage
  • Replace licensed clinical staff
  • Make an unreviewed clinical decision

The practice defines escalation paths for urgent, clinical, complex, or out-of-policy situations.

What we review before production

The scope of a security review depends on the approved workflow and deployment. Topics may include:

  • The data the workflow needs and data it should not collect
  • User roles, permissions, and staff review
  • Customer and tenant separation
  • Recordings, transcripts, exports, and integration access
  • Data transmission, storage, retention, and deletion
  • Administrative logging and incident escalation
  • Vendors and subprocessors involved in the approved environment
  • Customer notification and contractual requirements

This list describes review areas. It does not claim that a named certification, control, recovery target, or service level is available in every deployment. We confirm current evidence during the review.

Customer responsibilities

Organizations using EigenH AI remain responsible for:

  • Determining whether they are a HIPAA Covered Entity or Business Associate
  • Providing required patient notices
  • Obtaining required consent for calls, SMS, recordings, and automated communications
  • Configuring user permissions and approved workflows
  • Reviewing agent summaries, actions, and handoffs
  • Validating appointment and practice-management system updates
  • Following applicable healthcare, privacy, telephony, and professional rules

Data minimization

An administrative workflow should collect only the information needed for the approved task. Patient information, health details, insurance identifiers, and free text do not belong in website analytics or public support channels.

Do not send patient records, medical details, insurance information, or other PHI through the website contact or demo forms.

Where patient call data flows

A patient call follows one administrative path:

  1. The patient calls the practice number. EigenH AI answers on the practice’s behalf, inside the scripts and rules the office approved.
  2. The agent works the request within approved rules. Appointment types, provider availability, and escalation triggers all come from the practice — uncertain or out-of-policy requests go to staff.
  3. Approved actions are written to practice systems. Scheduling changes reach the practice-management system through NexHealth.
  4. Staff review the outcome. Every call ends with intent, outcome, transcript, and next step, and urgent conversations reach the team with context attached.

Data handled by the service is encrypted in transit and at rest, the production service runs on AWS, and the vendors in an approved environment are confirmed during the security review.

Data ownership

The practice owns its patient data. EigenH AI processes it to provide the contracted service, does not sell patient data, and does not use PHI for advertising. Export and deletion are handled under the applicable Customer Agreement and Business Associate Agreement.

Reporting a security vulnerability

Security researchers can report suspected vulnerabilities to support@eigenh.ai with “Security” in the subject line. We acknowledge good-faith reports, and we ask researchers to avoid accessing customer data while testing. A machine-readable contact record is published at /.well-known/security.txt.

Request a security, privacy, or contract review

Tell us which workflow and systems you are evaluating. We will confirm the review path, share the materials currently available, and put the BAA in place during scoping.

For privacy, security, contractual, or trust questions, contact support@eigenh.ai.

EigenH AI is operated by EigenH AI, Inc., a Delaware corporation. Its registered office at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States is provided for corporate identification only and is not a support or operating office.

Security questions

What buyers ask before a security review

Will EigenH AI sign a BAA?

Yes. A Business Associate Agreement is signed before production PHI is submitted — the agreement is in effect before PHI moves, not after. Tell us which workflow you are evaluating and we will put the BAA in place during scoping.

Is EigenH AI HIPAA certified?

No, and neither is anyone else. There is no certifying body for HIPAA and no product can be certified under it, so any vendor claiming a HIPAA certification is describing something that does not exist. EigenH AI is HIPAA compliant as a business associate: a signed BAA, defined administrative AI limits, and a security review before production.

Where is data processed?

The public website is hosted and delivered through AWS. Processing locations and any data-residency commitments for a customer deployment are defined in the applicable Customer Agreement or deployment documentation, and confirmed during the security review.

Is patient data used to train AI models?

No. EigenH AI does not use customer PHI to train general-purpose or foundation AI models. Where third-party AI providers support authorized workflows, EigenH AI uses configurations and terms intended to prevent customer content from training their general-purpose models, confirmed as part of vendor review.

Are patient calls recorded?

Recordings, transcripts, exports, and integration access are part of what a security review covers before production. The practice remains responsible for obtaining the consent that applicable law requires for calls, SMS, recordings, and automated communications.

What does a security review involve?

Scope depends on the approved workflow and deployment, and typically covers the data the workflow needs, user roles and permissions, tenant separation, recordings and integration access, retention and deletion, logging and incident escalation, and the vendors involved. We confirm current evidence during the review rather than publishing a blanket claim.

Start a security review