
Privacy Policy & AI Disclosures
How HealixAI protects your electronic health records (EHR), clinical data, and AI interactions through HIPAA-compliant encryption, stateless voice streams, and strict data sovereignty.
1. Clinical Data & SMART-on-FHIR Scopes
HealixAI utilizes the industry standard SMART on FHIR (Fast Healthcare Interoperability Resources) framework and official Medicare API channels to connect to electronic health records. We explicitly request read-only access to the following clinical scopes:
Strict Read-Only Guarantee:
HealixAI never requests write access to your primary medical record. We cannot alter, delete, or create records in your physician's hospital portal. All EHR synchronizations are strictly read-only.
2. AI Architecture & Zero Model Training Guarantee
HealixAI utilizes clinical machine learning and voice models under a signed Google Cloud Business Associate Agreement (BAA):
Absolute Zero Model Training Guarantee
Your personal health data, Medicare records, voice audio, and conversational transcripts are NEVER used to train public AI models, foundation LLMs, or third-party algorithms. All processing occurs statelessly in memory under signed BAAs.
3. Voice Streaming & Telephony Privacy
“All audio streaming happens statelessly over TLS 1.3 encrypted connections under our signed Google Cloud BAA. Our platform does not store raw voice recordings or audio transcripts on translation nodes, which keeps us fully compliant with HIPAA security rules.”
Both inbound SIP telephony calls and in-app WebRTC sessions terminate directly into ephemeral voice sessions. Call streams are destroyed immediately upon call termination.
4. Responsible AI Disclosure & Safety Reporting
While our clinical engine is grounded in validated medical literature (PubMed, AMA, CDC, CMS), AI systems may occasionally return unexpected outputs.
AI Safety & Error Reporting Channel:
If you observe any abnormal or unexpected AI behavior, contact our Clinical Safety Team immediately at ai-safety@healixai.com. Reports are reviewed by licensed physicians within 24 hours.
5. Data Retention & Right to Revoke
You maintain complete sovereignty over your health records. You may disconnect HealixAI access to your patient portal or Medicare.gov at any time.
- Upon account closure, all cached tokens and synchronized health data are cryptographically purged within 30 calendar days.
- To request immediate on-demand deletion of all records, email privacy@healixai.com. We execute and confirm data purging within 5 business days.
6. HIPAA Security & Encryption Standards
7. Privacy Officer & Governance Directory
Healix AI, Inc. / HealixAI, LLC
Clinical Leadership & AI Safety Officer: Ricardo Hamilton, MD
Privacy Inquiries & Deletion Requests: privacy@healixai.com
AI Safety Reporting: ai-safety@healixai.com
General Support: support@healixai.com