SECURITY & PRIVACY
PHI is removed before analysis. Not after.
Most vendors describe privacy as a policy. We describe it as a boundary in the architecture — because a policy can be violated and a boundary cannot.
THE BOUNDARY
Stripped at ingress. Not redacted at egress.
Many systems send identified clinical text to a model and remove identifiers from what comes back. Predisight does not. The model receives text that has already been de-identified. It has nothing to leak, because it was never given anything to leak.
THE COMMON APPROACH
Identified text reaches the model. Identifiers are removed from the output afterward. The model has seen the patient.
PREDISIGHT
Identifiers are removed before the model is called. The model has never seen the patient.
SECURITY & PRIVACY
The model never sees a name.
Identifiers are stripped before any clinical text reaches a model — not scrubbed from the output afterward. The link between a finding and a patient lives in a separate encrypted store the model cannot reach. This is architecture, not policy.
DE-IDENTIFICATION
Before any model call, not after.
PRIVACY METHOD
Pseudonymization with a separated identity store.
SUBPROCESSORS
AWS only.
HOSTING
HIPAA-eligible AWS, encrypted at rest and in transit.
BUSINESS ASSOCIATE AGREEMENT
Signed with AWS, executed with every facility.
ACCESS
Per-facility tenant isolation and audit logging.
DATA USE
Never sold, never used to train external models.
AUDIT TRAIL
Every finding traceable to a rule and a citation.
We describe our privacy posture precisely rather than generously. If your compliance officer wants the architecture, we will walk them through it.
DATA USE
What your data is never used for.
Never sold.
To anyone, for any purpose, ever.
Never used to train external models.
Your clinical documentation does not improve a vendor’s model. It generates findings for your facility and nothing else.
Never pooled across facilities.
Your data is not combined with another operator’s to build benchmarks, datasets, or products.
Never retained beyond your agreement.
On termination, your data is deleted on the schedule your BAA specifies.
ACCESS CONTROL
Your building. Your data. Your walls.
TENANT ISOLATION
Each facility runs in an isolated tenant. Data from one facility is not reachable from another, by another customer or by a shared query path.
AUDIT LOGGING
Access is authenticated and logged. Every retrieval of identified data leaves a record your team can pull.
STAFF ACCESS
Predisight staff do not browse facility data. Support access requires an explicit request, is time-limited, and is logged.
FOR YOUR COMPLIANCE OFFICER
The questions you may have
Will you sign a BAA?
Yes, before onboarding. It is a precondition, not a negotiation.
Is Predisight SOC 2 certified?
Not yet. We are early and we will not claim otherwise. We can walk your team through our controls in detail, and we will pursue formal audit as we grow.
Where does the data live?
HIPAA-eligible AWS services in a single US region. AWS is our only subprocessor.
Can the model be prompted to reveal patient information?
It has none to reveal. Identifiers are removed before any model call, and the identity mapping is held in a store the model has no path to.
What happens on termination?
Your data is deleted on the schedule specified in the BAA. We do not retain a copy.
Who at Predisight can see our data?
No one by default. Support access is requested, time-limited, and logged.
NEXT STEP
Send this page to your compliance officer.
If it does not answer their questions, we will get on a call and go through the architecture in detail.