HIPAA compliance
Workforce AI is HIPAA compliant. We sign Business Associate Agreements with customers who need one, and we run the administrative, physical, and technical safeguards that protect protected health information.
HIPAA compliance
Workforce AI is HIPAA compliant. We sign Business Associate Agreements with customers who need one and run the safeguards that protect PHI.
What HIPAA means for your firm
HIPAA is the U.S. law that governs how protected health information is handled. A vendor that creates, receives, maintains, or transmits PHI for a covered entity generally acts as a business associate. That relationship requires a written Business Associate Agreement (BAA) and a technically approved deployment before PHI is handled.
Our HIPAA compliance
Workforce AI has completed its HIPAA compliance work and is HIPAA compliant. Our safeguards are in force today across administrative, physical, and technical controls, covering the features, integrations, model providers, support paths, logs, backups, and sub-processors in scope.
Business Associate Agreement
A BAA defines permitted PHI use, safeguards, breach-reporting duties, subcontractor obligations, and what happens to PHI when service ends. Customers on an eligible plan can request a BAA, and we sign one when it is needed. Read our BAA information.
Safeguards in force
We enforce encryption in transit and at rest, role-based access controls, audit logging, and per-customer data isolation. Approved scope, executed agreements, and breach-response and subcontractor obligations are managed as part of every HIPAA-eligible deployment.
Subcontractors and sub-processors
Every provider in the PHI data path is reviewed for HIPAA eligibility and covered by the required agreement. Our current providers are listed on the sub-processors page.
Your responsibilities
On a HIPAA-eligible deployment, you remain responsible for appropriate access, authorizations, configuration, and use within the signed agreement and approved scope.
Request a BAA
Email privacy@hireworkforce.ai or contact us with the workflows and systems you need covered. Customers on an eligible plan can request a BAA, and you can review our program at the Workforce AI Trust Center.
What HIPAA means for your firm
HIPAA governs how protected health information is handled. A vendor handling PHI generally needs a written BAA and a technically approved deployment before that data is used.
Our HIPAA compliance
Workforce AI has completed its HIPAA compliance work and is HIPAA compliant. Our administrative, physical, and technical safeguards are in force today.
Business Associate Agreement
A BAA defines PHI use, safeguards, breach duties, subcontractors, and data return or deletion. Customers on an eligible plan can request one, and we sign it when needed. See our BAA information.
Safeguards in force
We enforce encryption in transit and at rest, role-based access, audit logging, and per-customer data isolation across every HIPAA-eligible deployment.
Subcontractors
Every provider in the PHI data path is reviewed and covered by the required agreement. See the sub-processors page.
Your responsibilities
On a HIPAA-eligible deployment, you remain responsible for appropriate access, authorization, configuration, and use within the approved scope.
Request a BAA
Email privacy@hireworkforce.ai or contact us to request a BAA. Review our program at the Workforce AI Trust Center.
Talk to a real person.
We will set up a BAA where you need one.