Last updated: August 7, 2026
HIPAA compliance
EigenH AI is HIPAA compliant and operates as a business associate to the practice. Approved workflows handle Protected Health Information and electronic Protected Health Information — PHI and ePHI — and a Business Associate Agreement is signed before production PHI moves.
HIPAA has no product certification and no certifying body, so we state the posture plainly instead of borrowing a badge: EigenH AI meets the HIPAA obligations that apply to it as a business associate, and the signed BAA makes those obligations contractual.
What has to be true before production PHI
Three things, all of them checkable:
- EigenH AI has approved the use case and production environment in writing. Approval is specific to a workflow and an environment, not a blanket account-level permission.
- A Business Associate Agreement is in effect. This is the “BAA Signed” status above — the agreement is executed before PHI moves, not after.
- The customer has completed the required security, access, consent, integration, and configuration steps. These are settled during the security review described below.
A customer’s use of EigenH AI does not make that customer compliant with HIPAA or any other law.
What EigenH AI is
EigenH AI, Inc. develops administrative workflow software for healthcare practices. EigenH AI is designed to help authorized teams manage patient calls, appointment requests, follow-up, staff tasks, and related front-desk work.
EigenH AI is not a healthcare provider, emergency service, medical device, or substitute for licensed clinical judgment.
Administrative AI boundaries
EigenH AI workflows must not:
- Diagnose a medical or dental condition
- Recommend treatment or medication
- Provide emergency medical triage
- Replace licensed clinical staff
- Make an unreviewed clinical decision
The practice defines escalation paths for urgent, clinical, complex, or out-of-policy situations.
What we review before production
The scope of a security review depends on the approved workflow and deployment. Topics may include:
- The data the workflow needs and data it should not collect
- User roles, permissions, and staff review
- Customer and tenant separation
- Recordings, transcripts, exports, and integration access
- Data transmission, storage, retention, and deletion
- Administrative logging and incident escalation
- Vendors and subprocessors involved in the approved environment
- Customer notification and contractual requirements
This list describes review areas. It does not claim that a named certification, control, recovery target, or service level is available in every deployment. We confirm current evidence during the review.
Customer responsibilities
Organizations using EigenH AI remain responsible for:
- Determining whether they are a HIPAA Covered Entity or Business Associate
- Providing required patient notices
- Obtaining required consent for calls, SMS, recordings, and automated communications
- Configuring user permissions and approved workflows
- Reviewing agent summaries, actions, and handoffs
- Validating appointment and practice-management system updates
- Following applicable healthcare, privacy, telephony, and professional rules
Data minimization
An administrative workflow should collect only the information needed for the approved task. Patient information, health details, insurance identifiers, and free text do not belong in website analytics or public support channels.
Do not send patient records, medical details, insurance information, or other PHI through the website contact or demo forms.
Where patient call data flows
A patient call follows one administrative path:
- The patient calls the practice number. EigenH AI answers on the practice’s behalf, inside the scripts and rules the office approved.
- The agent works the request within approved rules. Appointment types, provider availability, and escalation triggers all come from the practice — uncertain or out-of-policy requests go to staff.
- Approved actions are written to practice systems. Scheduling changes reach the practice-management system through NexHealth.
- Staff review the outcome. Every call ends with intent, outcome, transcript, and next step, and urgent conversations reach the team with context attached.
Data handled by the service is encrypted in transit and at rest, the production service runs on AWS, and the vendors in an approved environment are confirmed during the security review.
Data ownership
The practice owns its patient data. EigenH AI processes it to provide the contracted service, does not sell patient data, and does not use PHI for advertising. Export and deletion are handled under the applicable Customer Agreement and Business Associate Agreement.
Reporting a security vulnerability
Security researchers can report suspected vulnerabilities to support@eigenh.ai with “Security” in the subject line. We acknowledge good-faith reports, and we ask researchers to avoid accessing customer data while testing. A machine-readable contact record is published at /.well-known/security.txt.
Request a security, privacy, or contract review
Tell us which workflow and systems you are evaluating. We will confirm the review path, share the materials currently available, and put the BAA in place during scoping.
For privacy, security, contractual, or trust questions, contact support@eigenh.ai.
EigenH AI is operated by EigenH AI, Inc., a Delaware corporation. Its registered office at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States is provided for corporate identification only and is not a support or operating office.