Healthcare Provider? Request Your BAA Today.

All Covered Entities using Enitet Health must execute a Business Associate Agreement before accessing PHI. Request yours in minutes.

Request a BAA — [email protected]
1

Our HIPAA Compliance Commitment

Enitet Health is built from the ground up as a HIPAA-compliant AI healthcare platform. We handle Protected Health Information (PHI) on behalf of Covered Entities — including hospitals, clinics, SNFs, private practices, and FQHCs — and operate as a Business Associate under HIPAA (45 C.F.R. §§ 160–164).

Our compliance program encompasses the full scope of HIPAA's requirements: the Privacy Rule, the Security Rule, the Breach Notification Rule, and the administrative, technical, and physical safeguard standards of the HITECH Act. We do not treat HIPAA compliance as a checkbox — it is embedded in every layer of our platform architecture, operational processes, and workforce culture.

2

HIPAA Security Rule Safeguards

The HIPAA Security Rule (45 C.F.R. §§ 164.302–164.318) requires covered entities and business associates to implement three categories of safeguards. We implement all required and addressable specifications:

🔒

Technical Safeguards

AES-256 at rest (Firebase), TLS 1.3 in transit, MFA, RBAC, session timeouts, audit controls, PHI access logging, 2FA patient portal, Wazuh SIEM with 9 automated security agents

📋

Administrative Safeguards

Designated Security Officer, workforce training, risk analysis, risk management, BAA program, sanction policies, contingency planning, annual HIPAA risk assessment

🏢

Physical Safeguards

Google Cloud HIPAA-compliant data centers (US East/West only), Firebase HIPAA-compliant backend, facility access controls, workstation security policies, device and media controls, biometric access

Technical Safeguards — Detail

Administrative Safeguards — Detail

RCM & Claims Data Security

Firebase HIPAA InfrastructureAll PHI, including RCM claims data and MDS assessments, is stored exclusively on Firebase HIPAA-compliant infrastructure (US East/West regions) with AES-256 encryption at rest, TLS 1.3 in transit, Firebase HIPAA isolation, SIEM monitoring, and WAF/Shield protection. Firebase BAA is executed and maintained.
S

Security Monitoring & Facility Security Interface

Enitet Health operates a comprehensive security monitoring program that goes beyond standard HIPAA requirements. Built by a team with deep security operations expertise, our platform includes:

Automated SIEM Monitoring — 9 Security Agents

Our Wazuh SIEM platform runs 9 automated security agents on continuous schedules, covering every HIPAA Security Rule safeguard category:

AgentScheduleHIPAA RuleCoverage
Hourly Health CheckEvery hour§164.308(a)(1)(i)Security Management Process — agent connectivity, manager uptime, alert volume
Login Threat WatchEvery 15 min§164.312(b), §164.312(d)Audit Controls + Authentication — brute force, credential stuffing, unusual access
File Integrity & Malware WatchEvery 30 min§164.312(c)(1)Integrity Controls — filesystem changes, malware signatures, FIM alerts
SSL Certificate MonitorDaily 9 AM§164.312(e)(1)Transmission Security — cert expiry, weak ciphers, TLS compliance
MITRE ATT&CK WatchEvery 30 min§164.308(a)(1)(ii)(D)Activity Review — threat actor techniques, TTP pattern detection
SCA Compliance CheckDaily 6 AM§164.308(a)(8)Evaluation — Security Configuration Assessment scores across all agents
Daily Security BriefDaily 8 AM§164.308(a)(1)(ii)(D)Regular Review of Records — compiled 24h findings summary
Security WatchdogDaily 8 AM§164.312(b)Audit Controls — FIM monitoring, SSH access attempts
Compliance SyncEvery 30 min§164.312(b)Audit Controls — Wazuh compliance data synchronization to audit trail

Security Scorecard — Built Into Every Facility

Every Enitet Health subscriber gets a real-time Security Scorecard — a visual dashboard of their facility's security posture. The scorecard displays:

Facility Security Interface — Now Live

Every facility subscriber has access to their own Security Center — a dedicated security management dashboard within the Enitet Health platform. Facility administrators can view real-time compliance scores, active threat counts, MFA adoption rates, password health metrics, and session security settings — all filtered to their specific facility. This makes Enitet Health the only EHR that treats security as a product feature, not an afterthought.

Security LeadershipEnitet Health's security program is led by a founder with deep security analysis and SIEM operations expertise. Our monitoring infrastructure runs 24/7 with automated alerting to ensure threats are detected and escalated within minutes, not hours.
3

Business Associate Agreements (BAAs)

Under HIPAA, when a Business Associate handles PHI on behalf of a Covered Entity, a signed BAA is mandatory. Enitet Health maintains BAAs in two directions:

BAAs We Execute with Covered Entities (Our Customers)

Any healthcare provider, hospital, clinic, SNF, or other Covered Entity using Enitet Health must execute a BAA with us. We offer a standard BAA that meets all HIPAA requirements. Enterprise customers may negotiate terms through the Order Form process.

To request a BAA: Email [email protected] with subject line "BAA Request." We will provide the agreement within 3 business days. A signed BAA must be on file before any PHI flows through the Platform.

BAAs We Execute with Our Subcontractors

SubcontractorRoleBAA Status
StediClaims submission, prior auth, ERA enrollment✓ BAA Executed
Hathr AIHealthcare AI for prior auth and RCM predictions✓ BAA Executed
Comp AIAI-powered clinical documentation and templates✓ BAA Executed
DoesspotE-prescribing (EPCS for controlled substances)✓ BAA Executed
TwilioSMS, video, secure messaging✓ BAA Executed
Firebase / Google CloudDatabase, hosting, authentication✓ BAA Executed
StripePayment processing✓ BAA Executed
EDI PartnersClaims, prior auth, insurance verification✓ BAA Executed
SendGridEmail communications✓ BAA Executed
Firebase / Google CloudHIPAA-compliant cloud infrastructure✓ BAA Executed
iQIES/HARP (CMS)MDS assessment submissions✓ CMS System
No PHI Without a BAAEnitet Health does not permit any subcontractor or vendor to access, process, or transmit PHI until a Business Associate Agreement is fully executed. Make.com is currently limited to non-PHI demo automation until its BAA is complete.
4

Breach Notification Policy

Enitet Health maintains a documented Breach Notification Policy in full compliance with the HIPAA Breach Notification Rule (45 C.F.R. §§ 164.400–164.414) and the HITECH Act. Our policy covers detection, risk assessment, notification, and post-incident remediation for all PHI, including RCM claims data and MDS assessments.

Breach Definition & Exceptions

For purposes of this policy, a "Breach" means the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises the security or privacy of the PHI. Exceptions include:

Breach Scenarios Specific to Enitet Health

Breach Response Timeline

Third-Party Vendor Breach Protocol

If a Business Associate (Stedi, Firebase, Twilio, Stripe, SendGrid, Hathr AI, Comp AI, Doesspot) experiences a breach affecting Enitet Health PHI:

Facility Responsibility for Breach Response

Facilities using Enitet Health RCM, claims, or MDS services remain responsible for:

Breach Documentation & Retention

For each breach (including those determined to have low probability of compromise), Enitet Health maintains documentation including:

Report a Security ConcernIf you suspect unauthorized access to PHI, claims data, MDS assessments, or any security vulnerability, contact our Security team immediately: [email protected] or call 205-855-4545. We respond to all security reports within 4 hours. Facilities must report suspected breaches within 24 hours.
Facility Breach Reporting ObligationFacilities experiencing a breach involving their own systems that affects PHI processed through Enitet Health must notify Enitet Health within 24 hours of discovery. Failure to timely notify may result in termination of RCM services and indemnification liability.
5

Audit, Monitoring & Risk Assessment

Continuous Monitoring

Billing Accuracy & Anti-Upcoding Audits

Periodic Assessments

Audit Log Retention

All PHI access audit logs are retained for a minimum of 6 years from the date of creation, as required by the HIPAA Security Rule (§ 164.312(b)) and the general documentation retention standard (§ 164.530(j)). Claims and MDS submission logs are retained for 10 years per CMS requirements (42 C.F.R. § 422.504(d)).

Third-Party Vendor Audits

Compliance Reporting

Audit CommitmentEnitet Health conducts regular internal audits to ensure billing accuracy, detect potential upcoding, and verify CMS compliance. Facilities may request audit results related to their own claims data upon reasonable notice.
6

HIPAA Privacy Rule Compliance

Enitet Health complies with the HIPAA Privacy Rule (45 C.F.R. Part 164, Subpart E) governing the use and disclosure of Protected Health Information (PHI), including RCM claims data, MDS assessments, and mental health records:

Core Privacy Rule Standards

RCM & Claims Data Privacy

AI & PHI Privacy — 35+ Features

Family Portal & Patient-Controlled Access

Special Privacy Protections

Business Associate Privacy Obligations

Patient-Controlled PrivacyEnitet Health puts patients in control of their PHI. Family access requires your authorization and can be revoked at any time. AI training opt-out is available. You have full HIPAA rights to access, amend, and restrict your health information across all 35+ AI features.
7

Anti-Upcoding & Billing Accuracy Commitment

Enitet Health expressly commits to the following billing and coding compliance standards to align with the federal Anti-Kickback Statute (42 U.S.C. § 1320a-7b(b)) and Stark Law personal services safe harbor (42 C.F.R. § 411.357(d)):

Our Commitments

Anti-Kickback ComplianceOur compensation structure (fixed platform fee + 0.5% RCM fee based on collected revenue) is set in advance, commercially reasonable, and not determined by referrals. Clinical coding is excluded from RCM services, reducing risk under the Anti-Kickback Statute.
8

Contact Our Compliance Team

Enitet Health Inc.
254 Chapman Rd, Ste 208-28331
Newark, DE 19702

For all HIPAA compliance inquiries, BAA requests, breach reports, and regulatory questions:

Our CommitmentEnitet Health will not retaliate against any patient, provider, or employee who exercises their HIPAA rights or files a good-faith complaint with HHS OCR or any other regulatory authority.