Security & HIPAA posture

Clear boundaries for a sensitive workflow.

ChronMD keeps medical records off this website and out of email. Records move only through case-specific encrypted links into a HIPAA-eligible AWS environment, and every case is human-reviewed and hash-sealed before delivery.

Handling and review

Where records go — and where they never go.

This marketing site never receives records at all. Case intake, processing, and delivery are separated from the public website, so your team always knows where information belongs.

Full plain-language details are in the HIPAA notice, Privacy policy, and Terms of service.

Encrypted, case-specific upload links

After scope confirmation, records upload through a private, expiring, presigned link straight into encrypted S3 storage. Upload links expire in 24 hours; delivery links expire after 7 days.

Encrypted in transit and at rest

TLS in transit; server-side encryption with AWS KMS-managed keys at rest. Storage is non-public, access-logged, and reachable only through short-lived signed URLs and least-privilege credentials.

BAA-backed, HIPAA-eligible processing

PHI is processed only on HIPAA-eligible AWS services (S3, Textract OCR, Bedrock AI) covered under the standard AWS Business Associate Agreement. Records never leave AWS, and the model provider never sees inputs or outputs.

No records by email — ever

Email is for scheduling, links, and receipts only. If PHI arrives by email in error, we delete it and re-route through a secure link. No uploads, logins, or case data on this website.

Human review before delivery

A trained human reviewer checks every deliverable against the source records before it ships. Nothing goes out on AI output alone.

Sealed audit ledger

Every input, intermediate, and output file is SHA256-hashed into a tamper-evident, independently re-verifiable case ledger — the full processing history of any case, on demand.

The fine print, in plain language

Read the full notices.

The complete data-handling architecture, subprocessor list, retention periods, and BAA process are documented in plain language — not buried.

HIPAA notice

Where PHI lives and where it never goes, safeguards, the AWS BAA, subcontractors, and breach notification.

Privacy policy

What this website collects, how case data is processed as part of the service, and retention.

Terms of service

Scope of the service, payment, delivery, confidentiality, and limitations.

BAA requests and security questions: intake@chronmd.com