HIPAA Compliance
Gimerny AI is built to handle protected health information (PHI) in compliance with the Health Insurance Portability and Accountability Act. Our platform enables pharmaceutical companies and research institutions to leverage AI on sensitive patient data without compromising regulatory compliance.
Administrative Safeguards
- Designated HIPAA Privacy Officer and Security Officer
- Workforce training program with annual recertification
- Business Associate Agreements (BAAs) with all subprocessors
- Risk analysis conducted annually by independent assessors
- Incident response plan with 60-day breach notification procedures
- Sanctions policy for workforce members who violate policies
- Contingency plan including backup, disaster recovery, and emergency operations
Physical Safeguards
- AWS and GCP data centers with SOC 2 Type II certification
- Biometric and card-key access to server facilities
- 24/7 video surveillance and security staffing
- Environmental controls (fire suppression, climate, redundant power)
- Secure media disposal with certificate of destruction
- Workstation security policies for all employees accessing PHI
- Device and media controls for portable equipment
Technical Safeguards
- Unique user identification and automatic logoff
- Encryption: AES-256 at rest, TLS 1.3 in transit
- Audit controls with immutable log retention for 7 years
- Integrity controls ensuring PHI is not improperly altered
- Person or entity authentication via MFA
- Transmission security with endpoint verification
- Emergency access procedures for critical system recovery
How We Handle PHI
Data Minimization
We collect and process only the minimum necessary PHI required for the specific service being provided. Our platform supports de-identification workflows that remove direct identifiers before AI model training.
Federated Learning
GimernyGenome supports federated learning, where AI models are trained across institutional boundaries without moving raw patient data. PHI never leaves the custodial institution's infrastructure; only encrypted model gradients are transmitted.
Access Controls
PHI is accessible only to authorized users with a documented business need. All access is logged, reviewed quarterly, and subject to role-based permissions. Emergency break-glass procedures are documented and audited.
Subprocessor Management
All subprocessors that may access PHI have executed Business Associate Agreements. We maintain a current list of subprocessors and notify customers 30 days before any changes. Current subprocessors include AWS (infrastructure), Stripe (billing, no PHI access), and Datadog (monitoring, no PHI in logs).
Breach Response
In the event of a breach involving unsecured PHI, we will notify affected covered entities within 60 days as required by the HITECH Act. Our incident response team follows documented playbooks, and post-incident reviews drive continuous improvement.
Additional Compliance Frameworks
SOC 2 Type II
Annual audit covering security, availability, and confidentiality trust service criteria. Report available under NDA.
GDPR
Full compliance with EU data protection regulation. DPA with SCCs available for all customers. EU data residency available.
ISO 27001
Certified information security management system covering all Gimerny AI operations. Certificate available on request.
GxP / 21 CFR Part 11
Platform supports validated workflows for GxP-regulated environments. Electronic signatures and audit trails meet FDA requirements.
Request Compliance Documentation
We provide SOC 2 reports, penetration test summaries, compliance questionnaire responses, and BAAs upon request. Contact our compliance team for details.
Contact Compliance Team