HIPAA Notice & Data Handling
When we touch protected health information, we treat it as what it is: someone’s most private record, entrusted to us. This page explains our role and our obligations.
Last updated · June 3, 2026
01 Our role
This public website is not a covered entity and is not intended to collect protected health information (PHI). Where our products process PHI, artificialBRIDGE generally acts as a business associate under the Health Insurance Portability and Accountability Act (HIPAA) and the HITECH Act, processing PHI only on behalf of, and under contract with, covered entities or other business associates.
02 What is PHI
Protected health information is individually identifiable health information — including the Medicare Beneficiary Identifier, diagnoses, claims, and enrollment data — that is created, received, maintained, or transmitted in connection with healthcare. We handle PHI only within products designed for it, never through public web forms.
03 Business Associate Agreements
Before processing PHI for a customer, we execute a Business Associate Agreement (BAA) that defines permitted uses and disclosures, required safeguards, and breach obligations. We flow equivalent terms down to any subcontractor that may handle PHI on our behalf.
04 Permitted uses & minimum necessary
We use and disclose PHI only as permitted by the applicable BAA and HIPAA — to provide the contracted services, for required management and administration, and as required by law. We apply the minimum-necessary standard, limiting access and use to what is needed for the task.
05 Safeguards
- Administrative: workforce training, access reviews, risk analysis, and documented policies.
- Physical: reliance on SOC 2-compliant cloud facilities with controlled physical access.
- Technical: encryption in transit and at rest, unique user authentication, audit logging, and automatic session controls.
See Information Security for the technical detail.
06 De-identification
Where analytics or model improvement is permitted, we prefer de-identified or aggregated data created in accordance with HIPAA's de-identification standards, so that information cannot reasonably be used to identify an individual.
07 Breach notification
If we discover a breach of unsecured PHI, we will notify the affected covered entity without unreasonable delay and no later than the timeframe required by the HIPAA Breach Notification Rule, providing the information needed for the covered entity to meet its own notification duties.
08 Individual rights
Individuals exercise HIPAA rights — access, amendment, accounting of disclosures — through the covered entity that maintains their record. As a business associate, we support our customers in fulfilling those requests as required by our BAA. If you are a beneficiary, contact your plan or provider; we will assist them as needed.
09 A note on Medicare
artificialBRIDGE is a technology vendor and is not affiliated with or endorsed by CMS, Medicare, or any government agency, and is not an insurance agency. We do not sell plans or steer beneficiaries toward any plan. To review all of your options, contact Medicare.gov or 1‑800‑MEDICARE (TTY 1‑877‑486‑2048).
10 Contact our Privacy Officer
For HIPAA or data-handling questions, including BAA requests: