AWS HIPAA-eligible infrastructure, executed BAAs, TLS 1.3/AES-256 encryption, zero-retention AI policies, and audit-ready logging. Your compliance team can sign off without hesitation.
ClaireMed is designed to support HIPAA compliance with infrastructure, vendor governance, and operational controls that meet OCR requirements. HIPAA compliance depends on both technology (what we provide) and operational controls (how you deploy it). ClaireMed provides HIPAA-compliant architecture; your compliance team verifies operational controls before pilot.
ClaireMed infrastructure uses only AWS covered services under executed AWS Business Associate Agreement (BAA):
S3: Call recordings, transcripts, audit logs (encrypted at rest)
RDS: Customer data, configuration (encrypted at rest)
Lambda/ECS in VPC: Isolated, encrypted network
KMS: Key management for all encryption
CloudTrail: AWS API activity, access logs
CloudWatch: Metrics, logs, alerts
ClaireMed has executed BAAs with all subprocessors that handle PHI:
| Subprocessor | Service | BAA Status |
|---|---|---|
| AWS | Infrastructure | ✓ Executed |
| Twilio Security Edition | Telephony | ✓ Executed |
| ElevenLabs | Text-to-Speech (TTS) | ✓ Executed |
| Deepgram | Speech-to-Text (STT) | ✓ Executed |
| OpenAI/Anthropic | LLM (Conversational AI) | ✓ Executed |
All storage (S3, RDS) encrypted with AES-256 using AWS KMS. Patient data, call recordings, transcripts, and configuration are encrypted by default.
TLS 1.3 for all network traffic. API calls, database connections, and telephony sessions use encrypted channels. No plaintext PHI on the wire.
AI vendors (OpenAI, Anthropic, ElevenLabs, Deepgram) do not train models on ClaireMed data and do not retain inputs/outputs.
Zero data retention policies. API inputs/outputs are not used for training or stored by the vendor.
No audio retention. Inputs are processed and discarded immediately after synthesis/transcription.
Every call generates an audit trail with immutable logs stored in S3 Object Lock (WORM mode) for 7 years.
Call start/end timestamps, caller ID, agent transfers, detected intents, patient-provided information (appointment changes, billing questions), and final disposition (transferred to human, voicemail, completed by AI).
ClaireMed executes a BAA with each medical practice customer.
Contact sales or send request to legal@clairemed.io
Standard BAA template, typically 5-7 days
Technical onboarding with BAA in place
Production rollout with compliance sign-off