HealixAI Logo
HIPAA & CMS HTI-1 Compliant • Zero PHI Retention

Privacy Policy & AI Disclosures

How HealixAI protects your electronic health records (EHR), clinical data, and AI interactions through HIPAA-compliant encryption, stateless voice streams, and strict data sovereignty.

Effective Date: April 1, 2026Last Updated: August 2026 (CMS Medicare & HTI-1 Certified)

1. Clinical Data & SMART-on-FHIR Scopes

HealixAI utilizes the industry standard SMART on FHIR (Fast Healthcare Interoperability Resources) framework and official Medicare API channels to connect to electronic health records. We explicitly request read-only access to the following clinical scopes:

Patient Profile & Demographics (Patient.read)
Medications & Prescriptions (MedicationRequest.read)
Clinical Conditions (Condition.read)
Laboratory & Vitals (Observation.read)
Medicare Claims Data (ExplanationOfBenefit.read)
Immunization History (Immunization.read)
Allergies & Intolerances (AllergyIntolerance.read)
Surgical Procedures (Procedure.read)
Diagnostic Imaging Reports (DiagnosticReport.read)
Insurance Benefits (Coverage.read)

Strict Read-Only Guarantee:

HealixAI never requests write access to your primary medical record. We cannot alter, delete, or create records in your physician's hospital portal. All EHR synchronizations are strictly read-only.

2. AI Architecture & Zero Model Training Guarantee

HealixAI utilizes clinical machine learning and voice models under a signed Google Cloud Business Associate Agreement (BAA):

Google Gemini Live S2SReal-time speech-to-speech voice companion operating over encrypted WebRTC audio pipes.
BigQuery Vector SearchIndexes 2.3M+ peer-reviewed PubMed articles for sub-150ms clinical citation grounding.
Clinical ML EngineNormalizes LOINC lab values and RxNorm medication categories for drug-drug interaction safety.

Absolute Zero Model Training Guarantee

Your personal health data, Medicare records, voice audio, and conversational transcripts are NEVER used to train public AI models, foundation LLMs, or third-party algorithms. All processing occurs statelessly in memory under signed BAAs.

3. Voice Streaming & Telephony Privacy

“All audio streaming happens statelessly over TLS 1.3 encrypted connections under our signed Google Cloud BAA. Our platform does not store raw voice recordings or audio transcripts on translation nodes, which keeps us fully compliant with HIPAA security rules.”

Both inbound SIP telephony calls and in-app WebRTC sessions terminate directly into ephemeral voice sessions. Call streams are destroyed immediately upon call termination.

4. Responsible AI Disclosure & Safety Reporting

While our clinical engine is grounded in validated medical literature (PubMed, AMA, CDC, CMS), AI systems may occasionally return unexpected outputs.

AI Safety & Error Reporting Channel:

If you observe any abnormal or unexpected AI behavior, contact our Clinical Safety Team immediately at ai-safety@healixai.com. Reports are reviewed by licensed physicians within 24 hours.

5. Data Retention & Right to Revoke

You maintain complete sovereignty over your health records. You may disconnect HealixAI access to your patient portal or Medicare.gov at any time.

  • Upon account closure, all cached tokens and synchronized health data are cryptographically purged within 30 calendar days.
  • To request immediate on-demand deletion of all records, email privacy@healixai.com. We execute and confirm data purging within 5 business days.

6. HIPAA Security & Encryption Standards

TLS 1.3 In-Transit EncryptionAll REST API calls, WebRTC media streams, and database queries use modern cryptographic ciphers.
AES-256 At-Rest EncryptionUser settings and cached metadata are encrypted at rest with managed Google Cloud KMS keys.
OAuth 2.0 / PKCE TokensShort-lived access tokens with automatic rotation prevent persistent credential exposure.
SOC 2 Type II ControlsContinuous automated security audits, vulnerability scanning, and role-based access control.

7. Privacy Officer & Governance Directory

Healix AI, Inc. / HealixAI, LLC

Clinical Leadership & AI Safety Officer: Ricardo Hamilton, MD

Privacy Inquiries & Deletion Requests: privacy@healixai.com

AI Safety Reporting: ai-safety@healixai.com

General Support: support@healixai.com