/Security

We don't train on your patients.

Some vendors treat customer data as training material for their models. We don't. What our agents know doesn't come from your patients, and what they learn about your clinic never leaves it.

No model training

Your patient data is never used to train or fine-tune AI models, ours or anyone else's.

Isolated to your site

Your guidance, playbooks, and workflow logic stay with your clinic. Nothing is shared with another customer.

Encrypted end to end

Patient data is encrypted in transit and at rest, across phone, text, and web.

( fig. 01 )

/How we operate

HIPAA compliant

Built for PHI from day one. We execute a Business Associate Agreement with every customer before any patient data moves.

Least-privilege access

Agents operate with scoped credentials and touch only the systems a workflow requires. The scope is mapped with you during onboarding.

Every action logged

Each call, message, and write to your EMR lands in a reviewable log: what happened, when, and why.

Human oversight

You define the handoff points. Clinical questions and unusual requests route to your team with full context.

Revocable at any time

Pause or revoke agent access per workflow or across the board, without waiting on us.

Data minimization

Agents collect only what a workflow needs to complete. Nothing extra is requested, and nothing extra is stored.

( fig. 02 )

/Independently monitored

Don't take our word for it.

Our HIPAA compliance is continuously monitored by Vanta, an independent third-party compliance platform. Vanta checks our systems around the clock, not once a year during an audit.

If a control drifts out of place, we know before it becomes your problem.

HIPAA monitoring · Vanta

HIPAA administrative safeguards

Encryption at rest and in transit

Access control & offboarding

Vendor risk management

Infrastructure vulnerability scans

Employee security training

Checked continuously

All controls passing

Reviewing us for your clinic?

We'll walk your compliance or IT team through our architecture, data handling, and BAA. Send your security questionnaire to privacy@shasta.health or bring it to the demo.

Book a Demo