HIPAA Compliance

Effective Date: January 1, 2026

The short version

We handle health data under the same rules you do, and we will sign a BAA. We never use your health data to train AI models. For sensitive work, the AI can run entirely inside your own cloud. The detail below is written for your compliance team.

Relay Vault is committed to maintaining full compliance with the Health Insurance Portability and Accountability Act (HIPAA). As a Business Associate to healthcare organizations, insurance carriers, and TPAs, we implement comprehensive safeguards to protect Protected Health Information (PHI).


1. Our Role Under HIPAA

When you use Relay Vault to process healthcare-related data, we act as a Business Associate as defined by HIPAA. This means:


2. Administrative Safeguards

We implement comprehensive administrative safeguards:


3. Physical Safeguards

Our infrastructure includes physical security measures:


4. Technical Safeguards

We employ robust technical controls to protect PHI:


5. Privacy Rule Compliance

We adhere to HIPAA Privacy Rule requirements:


6. Breach Notification

In the event of a breach involving PHI:


7. AI and PHI

When our AI features process PHI, we maintain strict controls:


8. Business Associate Agreement

We execute BAAs with all customers who process PHI. Our BAA includes:

To request a BAA, please contact compliance@relayvault.ai.


9. Subcontractors

We maintain a list of subcontractors who may have access to PHI:


10. Documentation & Retention

We maintain documentation required by HIPAA:

All documentation is retained for a minimum of 6 years as required by HIPAA.


11. Contact Us

For questions about our HIPAA compliance program, to request a BAA, or to report a potential security incident:

๐Ÿ“ง compliance@relayvault.ai

๐Ÿ”’ security@relayvault.ai (for security incidents)

๐Ÿ“ Relay Vault, LLC

San Francisco, CA