Home

HIPAA · GDPR · PDPL aligned · BAA-ready ·

HIPAA Disclosure

How Intel e-medix handles Protected Health Information.

When a US healthcare provider, clinic, or lab uses Intel e-medix to process PHI, we operate as a HIPAA Business Associate under a signed BAA. This page explains scope, safeguards, and how to obtain a BAA.

Important: The self-serve consumer version of Intel e-medix is an educational explanatory tool — it is not a diagnostic device and is not covered by a BAA. For any workflow that places PHI under HIPAA jurisdiction, you must be on the enterprise plan with a signed BAA before uploading patient data.

Safeguards in place

Administrative safeguards

Workforce access reviews, role-based permissions, security training, documented incident-response runbook, and a designated security/privacy contact.

Physical safeguards

PHI is hosted in SOC 2-aligned cloud data centers. No PHI lives on employee laptops or in shared drives.

Technical safeguards

AES-256 at rest, TLS 1.2+ in transit, row-level database policies, unique user IDs, session timeouts, and automatic 48-hour cryptographic erasure.

Audit controls

Every read, share, export, and deletion of PHI is logged with user, IP, and timestamp. Logs are tamper-evident and retained per BAA.

Request a Business Associate Agreement

Covered entities can request a BAA before transmitting any PHI. We return a standard BAA within 2 business days.

compliance@intelemedix.com
No. Intel e-medix operates as a technology vendor. When a US clinic, lab, or provider uses the platform to process Protected Health Information (PHI), Intel e-medix acts as a Business Associate under HIPAA and signs a Business Associate Agreement (BAA) with that covered entity.

This page summarizes Intel e-medix's HIPAA posture for general informational purposes. It is not legal advice and does not by itself create a Business Associate relationship — a signed BAA is required.