HIPAA Notice — How ChronMD Handles Protected Health Information
1. Our role
ChronMD (AIRSM LLC) reviews and summarizes medical records on behalf of law firms and legal professionals. Depending on how our client obtained the records and who the client is, ChronMD may act as a business associate (or subcontractor business associate) under HIPAA. Where HIPAA applies, we execute a Business Associate Agreement (BAA) with the client at onboarding, and that BAA governs our handling of protected health information (PHI). Where HIPAA does not technically apply (e.g., records obtained by counsel through authorization or discovery), we apply the same safeguards anyway.
2. Where PHI lives — and where it never goes
| System | PHI? | Notes |
|---|---|---|
| chronmd.com (this website, Hostinger) | Never | Static marketing pages only. No uploads, no login, no case data. |
| Stripe (payments) | Never | Checkout collects billing details only. Clients are instructed not to enter patient names or case details; we do not put PHI in Stripe products or metadata. |
| Email (intake@chronmd.com) | Never by design | Used for scheduling, links, and receipts. Clients must not attach records; if PHI arrives by email in error, we delete it and re-route through a secure link. |
| AWS intake & delivery storage (S3) | Yes | Private, encrypted buckets (SSE-KMS). Transfers only via short-lived signed URLs (uploads expire in 24 hours; download links in 7 days). Access logging enabled. |
| AWS processing (Textract OCR, Bedrock AI models) | Yes | Both are HIPAA-eligible AWS services covered by the AWS BAA. Records never leave AWS; the underlying AI model provider never sees inputs or outputs, and they are not used to train models. |
3. Safeguards
- Encryption: TLS in transit; server-side encryption with AWS KMS-managed keys at rest.
- Access control: non-public storage, least-privilege IAM credentials, no shared accounts, and expiring signed URLs as the only transfer mechanism.
- Auditability: every case is sealed with a SHA256 audit ledger covering every input, intermediate, and output file plus every processing step — tamper-evident and independently re-verifiable.
- Minimum necessary: we process only the records the client supplies, only to produce the ordered work product.
- Retention & deletion: case files are deleted from active storage after the retention period in our Privacy Policy or earlier on request; hash-only ledgers (no medical content) are retained as integrity records.
- Workforce: access to PHI is limited to personnel who need it to deliver or support the specific case, under confidentiality obligations and HIPAA awareness training.
4. AWS Business Associate Agreement
Our AWS account operates under the standard AWS Business Associate Addendum, and we restrict PHI workloads to HIPAA-eligible services (S3, SQS, Textract, Bedrock, SES, EC2, KMS, CloudWatch). Amazon Bedrock is a HIPAA-eligible service; when Claude models run on Bedrock, PHI stays inside AWS and the model provider (Anthropic) never receives it, so no separate model-provider BAA is required. If any non-AWS processing leg is ever introduced (e.g., an additional audit model), it will run only under an equivalent BAA or be kept PHI-free.
5. Subcontractors
We do not permit any subcontractor to handle PHI unless it is covered by a BAA chain equivalent to ours. Current PHI-handling subprocessor: Amazon Web Services. Stripe and Hostinger are business-operations providers that never receive PHI (see table above and the Privacy Policy).
6. Incident response and breach notification
We maintain an incident-response procedure. If we discover a breach of unsecured PHI, we will notify the affected client without unreasonable delay and within the timeframes required by the applicable BAA and 45 CFR §164.410, providing the information the client needs to meet its own notification obligations.
7. Client obligations
- Submit records only through the secure upload links we issue — never as email attachments.
- Do not include PHI in payment forms, email subject lines, or support requests.
- Confirm you are authorized to disclose the records to us for litigation-support purposes.
- Request a BAA at onboarding if your matter requires one — intake@chronmd.com.
8. Questions
Privacy and security questions, BAA requests, or deletion requests: intake@chronmd.com · AIRSM LLC, Jacksonville, Florida. Our registered mailing address is provided in executed agreements and on request.