HIPAA Notice of Privacy Practices
Effective date: August 15, 2026
Important: Meditrust AI is designed as a HIPAA-aware platform. While we implement HIPAA-aligned privacy standards, users should be aware that Meditrust AI may not meet the formal definition of a "covered entity" or "business associate" under HIPAA in all usage scenarios. This notice describes our privacy practices for health information.
Your Health Information Rights
You have the right to: request a copy of your health information stored on Meditrust AI; request corrections to your health records; receive a list of disclosures we have made; request restrictions on certain uses of your information; and file a complaint if you believe your privacy rights have been violated.
How We May Use Your Health Information
For treatment purposes: To facilitate connections with healthcare providers and lab services you request.
For operations: To improve our AI systems, ensure service quality, and train staff — always under strict confidentiality agreements.
With your authorization: For any other purpose, we will obtain your explicit written consent.
Safeguards We Implement
- ✓AES-256 encryption at rest for all health data
- ✓TLS 1.3 encryption in transit
- ✓Role-based access controls (minimum necessary principle)
- ✓Annual security risk assessments
- ✓Business Associate Agreements with all service providers
- ✓Breach notification procedures (within 60 days of discovery)
- ✓Staff HIPAA training and confidentiality agreements
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with Meditrust AI at privacy@meditrustai.com or with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa/filing-a-complaint.
We will not retaliate against you for filing a complaint.
