HIPAA Notice — How ChronMD Handles Protected Health Information

Effective date: July 2, 2026 · Last updated: July 2, 2026

This is a plain-language architecture and compliance notice, not a Notice of Privacy Practices under 45 CFR 164.520 (ChronMD is not a healthcare provider).

1. Our role

ChronMD (AIRSM LLC) reviews and summarizes medical records on behalf of law firms and legal professionals. Depending on how our client obtained the records and who the client is, ChronMD may act as a business associate (or subcontractor business associate) under HIPAA. Where HIPAA applies, we execute a Business Associate Agreement (BAA) with the client at onboarding, and that BAA governs our handling of protected health information (PHI). Where HIPAA does not technically apply (e.g., records obtained by counsel through authorization or discovery), we apply the same safeguards anyway.

2. Where PHI lives — and where it never goes

PHI is processed exclusively inside our access-controlled Amazon Web Services (AWS) environment. It never touches this marketing website, its hosting provider, our payment processor, or ordinary email attachments.
SystemPHI?Notes
chronmd.com (this website, Hostinger)NeverStatic marketing pages only. No uploads, no login, no case data.
Stripe (payments)NeverCheckout collects billing details only. Clients are instructed not to enter patient names or case details; we do not put PHI in Stripe products or metadata.
Email (intake@chronmd.com)Never by designUsed for scheduling, links, and receipts. Clients must not attach records; if PHI arrives by email in error, we delete it and re-route through a secure link.
AWS intake & delivery storage (S3)YesPrivate, encrypted buckets (SSE-KMS). Transfers only via short-lived signed URLs (uploads expire in 24 hours; download links in 7 days). Access logging enabled.
AWS processing (Textract OCR, Bedrock AI models)YesBoth are HIPAA-eligible AWS services covered by the AWS BAA. Records never leave AWS; the underlying AI model provider never sees inputs or outputs, and they are not used to train models.

3. Safeguards

4. AWS Business Associate Agreement

Our AWS account operates under the standard AWS Business Associate Addendum, and we restrict PHI workloads to HIPAA-eligible services (S3, SQS, Textract, Bedrock, SES, EC2, KMS, CloudWatch). Amazon Bedrock is a HIPAA-eligible service; when Claude models run on Bedrock, PHI stays inside AWS and the model provider (Anthropic) never receives it, so no separate model-provider BAA is required. If any non-AWS processing leg is ever introduced (e.g., an additional audit model), it will run only under an equivalent BAA or be kept PHI-free.

5. Subcontractors

We do not permit any subcontractor to handle PHI unless it is covered by a BAA chain equivalent to ours. Current PHI-handling subprocessor: Amazon Web Services. Stripe and Hostinger are business-operations providers that never receive PHI (see table above and the Privacy Policy).

6. Incident response and breach notification

We maintain an incident-response procedure. If we discover a breach of unsecured PHI, we will notify the affected client without unreasonable delay and within the timeframes required by the applicable BAA and 45 CFR §164.410, providing the information the client needs to meet its own notification obligations.

7. Client obligations

8. Questions

Privacy and security questions, BAA requests, or deletion requests: intake@chronmd.com · AIRSM LLC, Jacksonville, Florida. Our registered mailing address is provided in executed agreements and on request.