HIPAA · BAA in Place
We act as your Business Associate under a signed BAA, executed at signup. Microsoft Azure is under a BAA with us, and so is every subprocessor that handles PHI. HIPAA-eligible infrastructure from day one.
Built entirely on Microsoft Azure’s HIPAA-eligible infrastructure. Every layer engineered for healthcare-grade security and regulatory compliance.
Built entirely on Microsoft Azure's HIPAA-eligible infrastructure, under a signed Business Associate Agreement with Microsoft. Azure holds HITRUST CSF, FedRAMP High, ISO 27001, ISO 27018, and SOC 2 authorizations covering the infrastructure layer. Those are Azure's certifications, not ours — AHI's own SOC 2 Type 2 and HITRUST CSF are in progress.
Microsoft Azure is our infrastructure. Compute, storage, database, networking, key management, and real-time messaging all run on Azure under a signed Business Associate Agreement with Microsoft — this is where your data lives and where our APIs run. AI inference runs on OpenAI and Anthropic models, reached either through Azure's own AI endpoints or directly, depending on the workload; every path is covered by a signed Business Associate Agreement with zero data retention. Auth0 handles sign-in and Stripe handles billing; neither receives clinical content. That is the complete list — we publish every one of them, what they receive, and why. See the full subprocessor list →
Mission-aligned, not investor-driven. HALai, Inc. operates the platform as a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc., a 501(c)(3) non-profit. We do not sell your data, and we do not monetize patient information.
Dr. Merza leads security strategy and oversees every layer of AHI's infrastructure, from tenant isolation to AI processing controls. His work spans three decades of cybersecurity practice across enterprise systems, healthcare data environments, and government-grade threat analysis. At AHI, he owns the architecture that protects every encounter note flowing through the platform.
security@halai.aiCan other providers see my patients' data?
Is this HIPAA compliant?
Will my data be used to train someone else's product?
What happens if I want to leave?
Do I need my IT department to set this up?
Where is my data stored, and who else touches it?
What happens to documents I upload?
We don't monetize your patient data. HALai, Inc. is a wholly-owned subsidiary of Artificial Healthcare Intelligence, Inc., a 501(c)(3) non-profit. Every third party that touches your data is named on our subprocessor list.
We act as your Business Associate under a signed BAA, executed at signup. Microsoft Azure is under a BAA with us, and so is every subprocessor that handles PHI. HIPAA-eligible infrastructure from day one.
Our infrastructure provider, Microsoft Azure, holds HITRUST CSF, SOC 1/2/3, ISO/IEC 27001/27017/27018, and FedRAMP. Those are Azure's certifications. AHI's own SOC 2 Type 2 and HITRUST CSF are in progress.
AES-256 at rest, TLS 1.2 or higher in transit. Each provider's data in its own dedicated Azure container and partition. Private Link network isolation between our services.
OCR and document text extraction run in your browser, not on our servers. The source file never leaves your device — only the text you're working with does.
Executed as part of the Healthcare Provider User Agreement when you create your account — the standard clickwrap approach in healthcare software. A standalone countersigned BAA is available on request.
Export in standard formats for 90 days after termination, then return or destruction at your direction. U.S. data residency. Every subprocessor named publicly — see the list.
Request access to AHI's security documentation package, including our BAA, data architecture overview, subprocessor list, and pre-answered security questionnaire responses.
Request Security Package