HIPAA Compliance

How we protect your Protected Health Information

Last updated: January 29, 2026

MedTWIN AI is designed for HIPAA compliance. We implement administrative, physical, and technical safeguards required by HIPAA to protect the confidentiality, integrity, and availability of Protected Health Information (PHI).

1. Overview

The Health Insurance Portability and Accountability Act (HIPAA) sets national standards for the protection of sensitive patient health information. As a technology provider serving healthcare organizations and researchers, MedTWIN AI operates as a Business Associate under HIPAA.

This page outlines our commitment to HIPAA compliance and the safeguards we implement to protect PHI.

2. Our Compliance Framework

Administrative Safeguards

Security policies, workforce training, access management, incident response procedures, and regular risk assessments.

Physical Safeguards

Secure data centers with biometric access, 24/7 surveillance, environmental controls, and workstation security.

Technical Safeguards

Encryption, access controls, audit logging, automatic logoff, transmission security, and integrity controls.

Documentation

Comprehensive policies, procedures, risk assessments, and incident documentation maintained for 6+ years.

3. Business Associate Agreement (BAA)

MedTWIN AI provides Business Associate Agreements to covered entities and their business associates who require HIPAA compliance. Our BAA includes:

Request a BAA: Enterprise customers can request a Business Associate Agreement by contacting hipaa@medtwin.ai or speaking with their account manager.

4. Technical Security Controls

4.1 Encryption

4.2 Access Controls

4.3 Audit Controls

4.4 Transmission Security

5. Administrative Safeguards

5.1 Security Officer

MedTWIN AI has designated a Security Officer responsible for:

5.2 Workforce Training

5.3 Risk Assessment

6. Physical Safeguards

Our infrastructure is hosted in HIPAA-compliant data centers with:

7. Incident Response & Breach Notification

7.1 Incident Response

Our incident response plan includes:

7.2 Breach Notification

In the event of a breach involving PHI:

8. Subcontractors

We require all subcontractors who may access PHI to:

Key subcontractors include:

9. Patient Rights

We support covered entities in fulfilling patient rights under HIPAA:

10. Data Handling

10.1 Minimum Necessary

We implement the minimum necessary standard by:

10.2 Data Retention & Destruction

11. Compliance Verification

We demonstrate compliance through:

12. Contact Information

For HIPAA-related inquiries:

For security incidents, please contact us immediately at security@medtwin.ai with "URGENT: Security Incident" in the subject line.