Compliance — HIPAA

AI systems built around
HIPAA safeguards, not PHI access.

We don't position Dwayo as "HIPAA compliant" — that's an organizational program your covered entity runs, not something a vendor can claim off the shelf. What we build is a system architected so PHI stays inside your environment, with the access control, audit logging, and encryption your compliance program needs.

What this means

Safeguards,
not a badge.

HIPAA's Security Rule defines specific technical safeguards — access control, audit controls, integrity, transmission security. Those are things a system either has or doesn't; they're not a certification a vendor purchases. Every system we build maps directly to these safeguards, documented in writing before production code exists.

See our full Trust & Safety framework for the underlying architecture — this page is specifically how it applies when health information is in scope.

Control mapping

Security Rule safeguards,
mapped to what we build.

The same architecture decisions we make on every project, specifically mapped to HIPAA's technical safeguards.

HIPAA safeguardWhat we build
Access Control (§164.312(a))Role-based access control with a full access audit trail — who could see what, and when.
Audit Controls (§164.312(b))Every prompt, output, and model call logged, timestamped, and queryable.
Integrity (§164.312(c))Output schema enforcement and a documented data flow diagram covering every movement of data.
Transmission Security (§164.312(e))TLS 1.3 in transit, AES-256 at rest — key management stays with you, not us.
Minimum NecessaryPII/PHI redaction before any data reaches a language model — the "no PHI access" architecture described above.
Building with PHI

PHI stays
in your environment.

The practical version of "no PHI access": we build the AI layer to call into your existing systems through access-controlled interfaces, strip identifying information before it ever reaches a language model, and log every call. The model reasons over de-identified data; PHI itself never leaves your environment or sits in a prompt un-redacted.

01Redaction before the model

PII/PHI detected and stripped at the pipeline layer, before any call to a language model — not a policy, an architectural step.

02PHI never leaves your environment

Processing architected to run inside your infrastructure or VPC where PHI is involved, rather than routing it through a third party.

03A real conversation, not a default

If a project's requirements genuinely can't avoid direct PHI access, we discuss that explicitly — architecture options, risk, and whether a BAA makes sense — before scoping begins.

Why Dwayo

No sales pitch,
just how we work.

Four things that are true of every engagement, not just this one.

~6 weeks to first production feature

Built inside your existing stack — not a rewrite, and not a 7-month hiring cycle.

Priced by milestone, not by the hour

You know the number before you sign. No open-ended retainer.

Written Trust Spec before any code

Security, data handling, and compliance commitments on paper — not a verbal promise.

Full IP transfer, no lock-in

You own the code and the model config at project completion. We don't hold it hostage.

Common questions

Before you
book a call.

The questions we get asked most about HIPAA and AI — answered straight, no sales pitch.

Is your AI system HIPAA compliant?

No system is "HIPAA compliant" on its own — compliance is an organizational program your covered entity or business associate runs, not a product feature a vendor ships. What we build are systems designed to support your HIPAA Security Rule safeguards and produce the evidence your compliance program and auditors need.

Do you sign a Business Associate Agreement (BAA)?

Our default is to architect the system so PHI never reaches Dwayo or an external model un-redacted in the first place — de-identification and access controls mean we're not in a position where a BAA is the operative protection. If a specific project genuinely requires direct PHI access, we'll say so plainly and have that conversation before scoping begins, rather than defaulting to a BAA.

How do you handle PHI if you don't access it directly?

PHI stays inside your environment. We build the AI layer to call into your existing systems through access-controlled interfaces, with PII/PHI redaction pipelines stripping identifying information before anything reaches a language model, and full audit logs of every call.

What do you actually deliver for a HIPAA-relevant project?

The same Trust Spec we deliver on every engagement, with the compliance checklist section mapped specifically to the HIPAA Security Rule safeguards relevant to your system — access control, audit controls, integrity, and transmission security.

Get started

Tell us what
you're trying to build.

Book a 30-minute call — we'll tell you honestly what a HIPAA-relevant architecture would actually look like for your system.

01
Book a call30 minutes, no sales deck — just your stack and what you're trying to build.
02
We scope itA written Trust Spec and a fixed-milestone plan, not an hourly estimate.
03
We buildInside your existing stack — first production feature in about 6 weeks.