Security & Compliance

HIPAA readiness, a BAA where it applies, and no claim we cannot back

A Business Associate Agreement is available where applicable, and every security claim on this page points at the published Privacy Policy or Terms of Use it comes from.

System status report · Updated July 2026

Certification status

HIPAA is where the work is. We publish what is in place today, and we say plainly what is not.

  • BAA Ready

    HIPAA Readiness

    A Business Associate Agreement is available where applicable, and the service runs on AWS. Production PHI is accepted only after EigenH approves the use case and environment in writing and a BAA is in effect where required.

    STATUS: BAA_READY

  • Planned

    SOC 2 Type 2

    No SOC 2 audit is underway and no report exists. We will publish one when there is something to publish, rather than describe an audit we have not started.

    STATUS: PLANNED

There is no certifying body for HIPAA and no product can be "HIPAA certified", so we describe operational readiness instead. EigenH AI, Inc. holds no third-party security certification as of July 2026.

Security posture at a glance

Each row states what our published Privacy Policy and Terms of Use support today. Program commitments are labeled as such, and nothing here claims a certification or third-party audit.

Published today
BAA availability

A Business Associate Agreement is available where applicable. Production PHI may be submitted only after EigenH approves the use case and environment in writing and an appropriate BAA is in effect where required.

Terms of Use, HIPAA and BAAs
Program commitment
Encryption in transit and at rest

The security program is designed to address data protection for information in transit and in storage. We confirm the encryption standards for an approved environment during the security review instead of publishing a blanket claim.

Privacy Policy, Security
Published today
Access controls

Accounts carry roles and permissions, and authentication and security events are recorded. Customers give each authorized user an individual account, assign appropriate roles, and remove access that is no longer needed.

Terms of Use, Accounts and Access
Published today
Data residency

The public website is hosted and delivered through AWS. Processing locations and any data-residency commitments for a customer deployment are defined in the applicable Customer Agreement or deployment documentation.

Privacy Policy, Processing Locations
Published today
Data retention

Information is retained as long as reasonably necessary to provide the services and meet legal, contractual, security, and accounting requirements. Retention periods for customer service data depend on the customer's configuration, the applicable agreement, and the type of data. We do not publish fixed periods.

Privacy Policy, Data Retention
Published today
Subprocessors and vendors

The production website stack is named in the Privacy Policy: Google Tag Manager, PostHog, HubSpot, Cloudflare Turnstile, Sentry, AWS, and Resend. Appearing on that list does not approve a vendor for PHI. A provider that would handle PHI or ePHI requires a Business Associate Agreement or equivalent flow-down terms.

Privacy Policy, Cookies and Analytics
Program commitment
Audit logging

Authentication and security logs are among the technical information collected today, and logging and monitoring are stated design areas of the security program. The logging scope for a specific deployment is confirmed during the security review.

Privacy Policy, Security
Program commitment
Incident response

Incident response is a stated design area of the security program, and customers must notify EigenH of suspected unauthorized access. Notification duties and response commitments for a deployment are set in the applicable Customer Agreement or BAA. We do not publish a generic response-time guarantee.

Privacy Policy, Security

EigenH AI, Inc. holds no third-party security certification as of July 2026. Rows labeled "Program commitment" describe stated design areas of the security program, not audited controls. We confirm current evidence, including encryption standards and logging scope, during a pre-production security review.

Last updated: July 31, 2026

HIPAA readiness

EigenH is working toward operational readiness for approved workflows that may involve Protected Health Information or electronic Protected Health Information, often called PHI and ePHI.

HIPAA has no product certification, so we do not describe EigenH as certified under HIPAA and do not make an unconditional compliance claim. Whether HIPAA applies depends on the parties, the data, the workflow, the agreement, and the configured environment.

What has to be true before production PHI

Three things, all of them checkable:

  1. EigenH has approved the use case and production environment in writing. Approval is specific to a workflow and an environment, not a blanket account-level permission.
  2. A Business Associate Agreement is in effect where required. This is the “BAA ready” status above — the agreement is available and executed before PHI moves, not after.
  3. The customer has completed the required security, access, consent, integration, and configuration steps. These are settled during the security review described below.

A customer’s use of EigenH does not make that customer compliant with HIPAA or any other law.

What EigenH is

EigenH AI, Inc. develops administrative workflow software for healthcare practices. EigenH is designed to help authorized teams manage patient calls, appointment requests, follow-up, staff tasks, and related front-desk work.

EigenH is not a healthcare provider, emergency service, medical device, or substitute for licensed clinical judgment.

Administrative AI boundaries

EigenH workflows must not:

  • Diagnose a medical or dental condition
  • Recommend treatment or medication
  • Provide emergency medical triage
  • Replace licensed clinical staff
  • Make an unreviewed clinical decision

The practice defines escalation paths for urgent, clinical, complex, or out-of-policy situations.

What we review before production

The scope of a security review depends on the approved workflow and deployment. Topics may include:

  • The data the workflow needs and data it should not collect
  • User roles, permissions, and staff review
  • Customer and tenant separation
  • Recordings, transcripts, exports, and integration access
  • Data transmission, storage, retention, and deletion
  • Administrative logging and incident escalation
  • Vendors and subprocessors involved in the approved environment
  • Customer notification and contractual requirements

This list describes review areas. It does not claim that a named certification, control, recovery target, or service level is available in every deployment. We confirm current evidence during the review.

Customer responsibilities

Organizations using EigenH remain responsible for:

  • Determining whether they are a HIPAA Covered Entity or Business Associate
  • Providing required patient notices
  • Obtaining required consent for calls, SMS, recordings, and automated communications
  • Configuring user permissions and approved workflows
  • Reviewing agent summaries, actions, and handoffs
  • Validating appointment and practice-management system updates
  • Following applicable healthcare, privacy, telephony, and professional rules

Data minimization

An administrative workflow should collect only the information needed for the approved task. Patient information, health details, insurance identifiers, and free text do not belong in website analytics or public support channels.

Do not send patient records, medical details, insurance information, or other PHI through the website contact or demo forms.

Request a security, privacy, or contract review

Tell us which workflow and systems you are evaluating. We will confirm the appropriate review path, the materials currently available, and whether a BAA or other agreement applies.

For privacy, security, contractual, or trust questions, contact support@eigenh.ai.

EigenH is operated by EigenH AI, Inc., a Delaware corporation. Its registered office at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States is provided for corporate identification only and is not a support or operating office.

Security questions

What buyers ask before a security review

Will EigenH sign a BAA?

Yes, where applicable. A Business Associate Agreement is available for approved workflows, and it has to be in effect before production PHI is submitted where one is required. Tell us which workflow you are evaluating and we will confirm whether a BAA applies.

Is EigenH HIPAA certified?

No, and neither is anyone else. There is no certifying body for HIPAA and no product can be certified under it, so any vendor claiming a HIPAA certification is describing something that does not exist. We publish operational readiness instead: a BAA where applicable, defined administrative AI limits, and a security review before production.

Do you hold a SOC 2 report?

No. No SOC 2 audit is underway and EigenH AI, Inc. holds no third-party security certification as of July 2026. We will publish a report when one exists.

Where is data processed?

The public website is hosted and delivered through AWS. Processing locations and any data-residency commitments for a customer deployment are defined in the applicable Customer Agreement or deployment documentation, and confirmed during the security review.

Are patient calls recorded?

Recordings, transcripts, exports, and integration access are part of what a security review covers before production. The practice remains responsible for obtaining the consent that applicable law requires for calls, SMS, recordings, and automated communications.

What does a security review involve?

Scope depends on the approved workflow and deployment, and typically covers the data the workflow needs, user roles and permissions, tenant separation, recordings and integration access, retention and deletion, logging and incident escalation, and the vendors involved. We confirm current evidence during the review rather than publishing a blanket claim.

Start a security review