Security · what your review will ask, answered here

One business associate. One sub-processor list. Nothing kept that your BAA does not permit.

This page is written for the person running the security review. Every claim is specific enough to be checked, and the parts that are limits rather than guarantees say so.

Agreements

Garrison is your business associate under HIPAA.

You sign one business associate agreement, with Garrison. HIPAA permits a business associate to use subcontractors, and requires that any subcontractor that creates, receives, maintains or transmits protected health information on the business associate's behalf is bound to the same restrictions in writing (45 CFR 164.502(e) and 164.504(e)). You are not required to sign anything with a subcontractor of ours.

Every model provider that handles identifiable data on your behalf is bound to Garrison under those rules. A provider that only ever receives de-identified data is not handling protected health information and needs no agreement. Your sub-processor list, with the status of each provider, is attached to your BAA and updated with notice.

Preview and beta models. We never route patient data to a model its provider labels preview, beta or experimental. Several providers exclude those from their own commitments.

De-identification

Identifiers are removed before anything is stored.

On the standard plan, before any usage data is retained, we remove the identifiers on the HIPAA Safe Harbor list (45 CFR 164.514(b)(2)) from prompts and responses: names, geographic units smaller than a state, all elements of dates finer than the year, ages over 89, telephone and fax numbers, email addresses, social security, medical record, health plan, account, certificate and licence numbers, vehicle and device identifiers, URLs, IP addresses, biometric identifiers, full-face images, and any other unique identifying number or code.

Two limits, stated plainly. First, detection in free text is automated, and like every automated filter it is not a guarantee: the HHS guidance itself notes that clinical narrative can carry context that identifies a person even after the listed identifiers are gone. Second, the authority to de-identify at all comes from your BAA. HHS treats de-identification as a use of protected health information that a business associate may perform only when the agreement allows it, so the clause is explicit in ours, and you read it before you sign.

On the zero-retention plan none of this applies, because nothing is kept.

Logs

Every request is on the record. No prompt text is.

One line per request: caller key, team, model, provider, input and output tokens, cost at the provider's list price, timestamp, outcome, and the source address. Each key is a unique identifier for the calling service, which is the one field the HIPAA Security Rule itself asks for (45 CFR 164.312(a)(2)(i)).

The log holds no prompt or response text on either plan. It is kept six years, matching the Security Rule's documentation retention period (45 CFR 164.316(b)(2)), and is exportable for your auditor.

Retention

What is kept, by plan.

DataAt costZero retention
Prompts and responses, as sentNot keptNot kept
De-identified usage dataKept, as your BAA permitsNot kept
Request log (metadata only)Six yearsSix years
Provider-side retentionPer the provider's commitment; some newer models require a retention periodOnly providers and models with no retention requirement

Transit and storage

Encrypted in transit and at rest.

Incidents

You hear from us without unreasonable delay.

If we discover a breach of unsecured protected health information, we notify you without unreasonable delay and within the period your BAA states, with what we know at the time and what we learn after. The BAA sets out the contact, the content of the notice and the cooperation that follows.

FAQ

Review questions.

Do we need our own BAA with each model provider?

No. You sign with Garrison. Providers that handle identifiable data on your behalf are bound to Garrison as subcontractors under HIPAA, and your sub-processor list names them.

Where is the sub-processor list?

Attached to your BAA, with the status of each provider, and updated with notice when a provider is added or removed.

Is the de-identification certified?

No. It removes the identifiers on the HIPAA Safe Harbor list by automated detection, and we say plainly that automated detection is not a guarantee. We do not claim an Expert Determination.

How do we get the BAA?

Leave a work email below. The agreement arrives by email, reads in an afternoon, and a key follows the signature.

Start

Request the BAA.

Tell us where to send the agreement. It reads in an afternoon.