Security · what your review will ask, answered here
This page is written for the person running the security review. Every claim is specific enough to be checked, and the parts that are limits rather than guarantees say so.
Agreements
You sign one business associate agreement, with Garrison. HIPAA permits a business associate to use subcontractors, and requires that any subcontractor that creates, receives, maintains or transmits protected health information on the business associate's behalf is bound to the same restrictions in writing (45 CFR 164.502(e) and 164.504(e)). You are not required to sign anything with a subcontractor of ours.
Every model provider that handles identifiable data on your behalf is bound to Garrison under those rules. A provider that only ever receives de-identified data is not handling protected health information and needs no agreement. Your sub-processor list, with the status of each provider, is attached to your BAA and updated with notice.
Preview and beta models. We never route patient data to a model its provider labels preview, beta or experimental. Several providers exclude those from their own commitments.
De-identification
On the standard plan, before any usage data is retained, we remove the identifiers on the HIPAA Safe Harbor list (45 CFR 164.514(b)(2)) from prompts and responses: names, geographic units smaller than a state, all elements of dates finer than the year, ages over 89, telephone and fax numbers, email addresses, social security, medical record, health plan, account, certificate and licence numbers, vehicle and device identifiers, URLs, IP addresses, biometric identifiers, full-face images, and any other unique identifying number or code.
Two limits, stated plainly. First, detection in free text is automated, and like every automated filter it is not a guarantee: the HHS guidance itself notes that clinical narrative can carry context that identifies a person even after the listed identifiers are gone. Second, the authority to de-identify at all comes from your BAA. HHS treats de-identification as a use of protected health information that a business associate may perform only when the agreement allows it, so the clause is explicit in ours, and you read it before you sign.
On the zero-retention plan none of this applies, because nothing is kept.
Logs
One line per request: caller key, team, model, provider, input and output tokens, cost at the provider's list price, timestamp, outcome, and the source address. Each key is a unique identifier for the calling service, which is the one field the HIPAA Security Rule itself asks for (45 CFR 164.312(a)(2)(i)).
The log holds no prompt or response text on either plan. It is kept six years, matching the Security Rule's documentation retention period (45 CFR 164.316(b)(2)), and is exportable for your auditor.
Retention
| Data | At cost | Zero retention |
|---|---|---|
| Prompts and responses, as sent | Not kept | Not kept |
| De-identified usage data | Kept, as your BAA permits | Not kept |
| Request log (metadata only) | Six years | Six years |
| Provider-side retention | Per the provider's commitment; some newer models require a retention period | Only providers and models with no retention requirement |
Transit and storage
Incidents
If we discover a breach of unsecured protected health information, we notify you without unreasonable delay and within the period your BAA states, with what we know at the time and what we learn after. The BAA sets out the contact, the content of the notice and the cooperation that follows.
FAQ
No. You sign with Garrison. Providers that handle identifiable data on your behalf are bound to Garrison as subcontractors under HIPAA, and your sub-processor list names them.
Attached to your BAA, with the status of each provider, and updated with notice when a provider is added or removed.
No. It removes the identifiers on the HIPAA Safe Harbor list by automated detection, and we say plainly that automated detection is not a guarantee. We do not claim an Expert Determination.
Leave a work email below. The agreement arrives by email, reads in an afternoon, and a key follows the signature.
Start
Tell us where to send the agreement. It reads in an afternoon.