Physician FAQ / HIPAA and data
Patient data, protected by design.
AEGIS will operate as a Business Associate to your practice, under a signed agreement, before any protected health information is handled.
Yes, by design. AEGIS will operate as a Business Associate and execute a Business Associate Agreement with your practice before any protected health information is handled. The platform is being built to meet HIPAA requirements for handling protected health information.
On HIPAA-eligible cloud infrastructure, with encryption in transit and at rest, role-based access controls, and audit logging, as designed. SOC 2 Type II and HITRUST are on the security roadmap as the platform scales.
Only with explicit opt-in consent, and only in de-identified form. There is no opt-out research use: a patient who does not opt in is never included, and a patient who does opt in can withdraw later. Tokenization lets de-identified records be linked without exposing protected health information. Genomic data is the hard case. A whole-genome sequence is inherently re-identifiable, so it is not treated as de-identified under Safe Harbor alone; any research use of sequence data runs under an Expert Determination and its documented conditions.
AEGIS will follow established breach-notification procedures, including the obligations that apply under HIPAA. The Business Associate Agreement will define how notification responsibilities are shared.
AEGIS will carry the platform, hosting, and security operations. Your obligations will be defined by the Business Associate Agreement rather than added on top of your workflow.
General information, not advice. This page explains how AEGIS is designed to operate, and some items describe planned capabilities. Confirm specifics with your own counsel and the AEGIS team.