Zero data retention · Zero data collection · Zero patient data
Legal

HIPAA Compliance

Last updated: August 5, 2026

Our HIPAA Approach

SHOMA AI Health is an administrative document-processing tool for authorised hospital and clinic staff, built to help covered entities and business associates handle Protected Health Information (PHI) in line with the U.S. Health Insurance Portability and Accountability Act (HIPAA). This page summarises the safeguards relevant to customers. No PHI is stored or retained: all clinical content is cancelled and permanently deleted immediately after the temporary report is generated.

Business Associate Agreement (BAA)

Where we process PHI on your behalf, we make a Business Associate Agreement available on eligible paid plans. A signed BAA governs permitted uses and disclosures, safeguards, breach notification, and subcontractor obligations.

Safeguards

  • Access controls

    Authentication and authorization restrict access to accounts and data.

  • Transmission security

    Data is transmitted over encrypted (TLS) connections.

  • Content protection

    Documents submitted for analysis are protected in transit using envelope encryption.

  • Minimum necessary

    We process only the data needed to produce the temporary report you request.

  • Zero retention

    Source documents and generated reports are permanently deleted immediately after delivery. No backups of clinical content are kept.

  • Professional access only

    Accounts and API keys are issued to authorised hospital and clinic staff. Patients have no access to the system.

Customer Responsibilities

HIPAA compliance is shared. Customers are responsible for having a signed BAA in place before submitting PHI, ensuring only authorised professional users access the service, reviewing every AI-generated report before any clinical use, and ensuring a lawful basis for the data they submit. All final clinical decisions remain the sole responsibility of the licensed healthcare professional.

Requesting a BAA

To request a BAA or ask about our HIPAA posture, contact us via the Contact page.