Compliance pack
BAA inventory, HIPAA SRA technical controls, audit-hash construction, and infrastructure topology — everything a BD legal or compliance counsel typically asks for in early diligence. Full source documents available on request.
Download the single-PDF Compliance Pack
Always-current version. Generated from the canonical source documents in our launch-prep repo at build time.
Download Compliance Pack (PDF) →BAA matrix
| Vendor | Scope | Status |
|---|---|---|
| AWS (Textract + S3 + Lightsail) | Document OCR, encrypted offsite backups, public TLS gateway | Signed 2026-05-08 |
| Google Workspace | Operator mailbox + admin email | Signed 2026-05-12 |
| Paubox | Transactional email (HIPAA Email API) | Signed 2026-05-16 |
| Stripe | Payments (PHI-free) | Conduit exception |
| Cloudflare | DNS only — proxy disabled | N/A |
Drug-agnostic recommendation hash
The chart-to-prior-authorization pathway records a SHA-256 hash of the clinical input tuple before any funding-source attribution is applied. Other generation paths must not be described as carrying this evidence until they write the same governed record.
This hash is implementation evidence for that specific pathway, not a blanket legal conclusion or a substitute for contract and compliance review.
What we'll provide on request
- Full HIPAA Security Risk Assessment (technical + administrative controls).
- BAA executed copies for AWS, Workspace, Paubox.
- Incident response plan (rev 3, 2026-05-09).
- Architecture diagram + key/secret rotation policy.
- Pre-launch checklist + offsite backup DR runbook.
- SOC 2 Type I scoping document (engagement targeted Q3 2026).
Contact: mic@denialhelp.com · Michael John Ryan, Privacy Officer, DenialHelp, LLC.