Caretech AITechnology that Cares
HIPAA

HIPAA — what applies, and what is not guaranteed.

Caretech AI makes no claim of HIPAA compliance, HIPAA certification or HIPAA readiness, here or anywhere else on this site. HIPAA has no vendor certification scheme; compliance is a property of a covered entity's operations, and of the contracts underneath them.

This page states where HIPAA could become relevant to work with Caretech AI, what remains the client's responsibility, and what Caretech AI does not guarantee.

Scope

Where HIPAA could apply

Caretech AI may support healthcare organizations that are subject to HIPAA in the United States.

Whether Caretech AI would create, receive, maintain or transmit Protected Health Information on behalf of a covered entity or business associate — and therefore whether it would be a business associate at all — depends entirely on the specific engagement, the data involved and the implementation model. None of that is settled by a website, and this page does not attempt to settle it.

Caretech AI is not creating, receiving, maintaining or transmitting Protected Health Information on behalf of any covered entity today, and no such arrangement is asserted on this page.

Business Associate Agreement

This page makes no BAA claim

No Business Associate Agreement is asserted, offered, or described as available here. Whether a BAA would be required, and whether Caretech AI would execute one, is a question for a specific engagement and for counsel on both sides.

Caretech AI will answer the BAA question in writing, for a specific engagement, once the position can be stated plainly. A hedged answer to this question is worth less than no answer, so none is published here in either direction.

If you need a definitive answer before proceeding, ask for it directly and expect a document rather than a web page.

Client responsibility

What remains with the client

Caretech AI products and services should be configured and used by clients in accordance with their own HIPAA obligations, internal policies, security procedures, and applicable legal requirements.

That includes account management, user access and permissions, workforce training, device and endpoint security, and the security of any third-party system a client chooses to connect. A vendor can supply controls; only the covered entity can operate them.

Not guaranteed

What Caretech AI does not guarantee

Caretech AI does not guarantee HIPAA compliance for a client's overall operations, workflows, integrations, user behavior, device security, third-party systems, or data handling outside Caretech AI-controlled environments.

This page makes no encryption claim, no audit-logging claim, and no safeguard inventory. HIPAA safeguards are mandatory for a business associate, and a mandatory control presented conditionally overstates what can be evidenced. When each can be stated unconditionally and evidenced, it will be stated unconditionally.

What the security practice does consist of — role-based access control, secure authentication and authorization, traceability for key system activities, and per-transaction tenant isolation enforced in the database — is set out on the Trust Center, with the scope boundaries that go with it.

What the security practice does consist of

Ask the BAA question directly.

If a Business Associate Agreement is a gate for your organization, raise it in the first conversation rather than the fifth. The answer will be the same either way — it will just cost less to hear it early.