HIPAA Compliance & Data Security
How ImplicitifyAI protects clinical data with encrypted transit and storage, opaque patient link tokens, deterministic scoring, and an in-portal BAA process for licensed clinicians.
Architecture: Encrypted, private-server design
Consumer and researcher assessments are delivered, captured, and scored on the basis of opaque tokens — not patient identities. All data is encrypted in transit and at rest. For the clinician patient-link workflow, access is limited to the treating clinician and their practice, and internally to authorized personnel under a Business Associate Agreement on a need-to-know basis.
Opaque Token Links
Each patient assessment is delivered via a randomly generated UUID token. No name, no date of birth, no identifying information is embedded in or associated with the link on our servers.
Alias-Only Profiles
Clinicians may optionally create a client profile using a self-chosen alias (e.g., 'Client A'). The platform never prompts for or stores the patient's real name.
Retention Under Clinician Control
Clinician-linked results are retained until the clinician or their practice deletes them. Clinicians control the retention of their own patient-link data.
Deterministic Scoring Engine
Scores are computed by a deterministic, published algorithm — fully reproducible and auditable, with no LLM inference in scoring. Where an optional model-written narrative is offered, it is generated separately from the deterministic scores and disclosed as such.
Encryption in Transit & at Rest
All data is encrypted in transit via TLS 1.2+ and encrypted at rest using industry-standard key management. Access logs are retained for 90 days.
Role-Based Access Control
Clinician accounts have access only to their own client tokens and reports. No cross-clinician data access is possible by default.
What ImplicitifyAI is — and is not
ImplicitifyAI is an automated assessment software platform used by licensed clinicians as an administration and scoring tool. It is not a covered entity under HIPAA by default — it operates as a business associate when clinicians who are covered entities use it to administer assessments to their patients.
- The platform does not provide clinical services. Scores and reports are professional outputs used by clinicians in their practice.
- The administering clinician retains clinical and legal responsibility for patient data under their applicable privacy regulations.
- Assessment data sent to patients via token links is not visible to ImplicitifyAI staff unless a clinician expressly opens a support ticket referencing a specific token.
✓ Business Associate Agreement (BAA)
A BAA is available to licensed clinicians who are covered entities under HIPAA, and is completed inside the clinician portal. BAA execution is required before patient links can be created for US patients in covered practice contexts.
Scope & limitations
This page is a description of our current technical posture, not a formal legal claim. Final wording of any BAA or data-processing addendum governs. This page was last updated May 1, 2026. If you have specific compliance questions, contact your institutional legal or compliance team.
- ImplicitifyAI is hosted on US-based cloud infrastructure.
- Database servers are located in the US.
Questions about our security posture or BAA process?
Contact us →Page last updated: May 1, 2026