HIPAA & Business Associate Notice
How CarePath sits relative to HIPAA, and when a BAA applies.
- Effective
- September 15, 2026
- Last updated
- September 15, 2026
- Operator
- Artemius Labs LLC
CarePath is a documentation tool, not a healthcare provider. It does not practise medicine, diagnose, triage, prescribe, calculate doses or check interactions, and it never replaces a clinician's own judgment or instructions.
The honest summary: CarePath is designed so that identifiers never persist, which is a strong position — but PHI does pass through the de-identification boundary. If your organization requires a BAA for that, ask us for one before you use the service on real cases.
Where CarePath sits
Most US clinicians and their organizations are covered entities under HIPAA. A vendor that creates, receives, maintains or transmits protected health information (PHI) on a covered entity’s behalf is a business associate, and needs a Business Associate Agreement (BAA).
CarePath is built to avoid holding PHI at all. Text and documents pass through a de-identification service before anything is stored, and only de-identified content is saved. The intent is that what remains in the system is de-identified health information, which HIPAA does not regulate.
Design intent is not a legal conclusion. PHI does transit the de-identification boundary — unavoidably, because clinicians paste real notes and upload real documents. If your organization treats that transit as disclosure to a business associate, you need a BAA with us before you use the service with real patient material.
Getting a BAA
Write to support@carepath.com with the subject “BAA request”, naming your organization, the covered entity, and the plan you are on or intend to buy. We will tell you whether we can execute one for your use case, on what terms, and on which plans.
Until a BAA is signed by both parties, do not submit PHI to CarePath. Use the service with instruction text you have written that contains no identifiers. This obligation is repeated in the Terms and the Acceptable Use Policy, and breaking it is a material breach.
Where a BAA is in place, it governs PHI and prevails over any conflicting term in the Terms of Service or the Privacy Policy for that data.
Safeguards we already operate
Whether or not a BAA applies, these controls are built and tested today:
- Technical. Encryption in transit and at rest; row-level security isolating one organization from another; a de-identification service with its own keys that runs in memory, writes nothing to disk and exposes no endpoint returning data; a signed receipt required before the database accepts case text; an independent second check that rejects failed output rather than passing it through.
- Administrative. Least-privilege access to production, logged and reviewed; role-based permissions inside the product; immediate session termination when a member is removed; a 30-minute idle timeout for shared workstations; an append-only audit log that no one — including our own jobs — can alter.
- Sharing. Nothing reaches a patient before a clinician approves it. Share links carry at least 128 bits of randomness, expire, can be revoked instantly, and are excluded from indexing.
The full description is on the Security page; the vendors involved are listed on Subprocessors.
What stays your responsibility
HIPAA compliance is a property of your organization’s practice, not of a vendor’s software. A BAA does not make you compliant, and neither does using CarePath. You remain responsible for:
- your minimum necessary determinations, notice of privacy practices, and patient authorisations;
- deciding whether sending a patient a link over an unencrypted channel is appropriate, and documenting that decision;
- checking each comic for residual identifying detail before approving it, including detail identifying by rarity or context;
- managing who in your organization has a seat, and removing leavers promptly;
- your own risk analysis, workforce training, and incident response;
- state privacy law, which is often stricter than HIPAA, and non-US law where you practise.
Incidents
If we become aware of an incident affecting your organization’s data, we notify the organization without undue delay and in any event within 72 hours, with what we know, what we are doing about it, and what you should do. Where a BAA is in place, its notification terms apply in addition.
Report a suspected incident or vulnerability to support@carepath.com.
This is not legal advice
This page describes how the product is built and what we will sign. It is not legal or compliance advice, and it is not a representation that your use of CarePath is HIPAA compliant. Whether it is depends on facts we do not control. Take your own counsel, and run your own risk analysis, before putting patient material into any vendor’s system.
Questions about this document
Write to us and we'll answer within 5 business days. Use the email address on your account so we can find you.
support@carepath.comArtemius Labs LLC1209 Mountain Road Pl NE, Ste RCheyenne, WY 82001United States