HIPAA

HIPAA-compliant services

Bwenzi LLC · July 2026

When we handle protected health information, we do it as a Business Associate under a signed agreement, and we hold every tool in the path of that data to the same standard.

Business Associate Agreements

We sign a Business Associate Agreement (BAA) with a covered entity or business associate before any protected health information (PHI) reaches us. The BAA governs how we may use and disclose that information, the safeguards we owe it, and how it is returned or destroyed when the work ends.

Our tools are under BAAs too

PHI touches only services that are themselves covered by a BAA with us. That includes hosting, storage, and the development and AI tooling we use on that work. A tool that cannot be placed under a BAA is not used with PHI. We do not paste PHI into general-purpose AI assistants, and we do not use PHI to train models.

Safeguards

Training

Bwenzi's owner holds current certificates in HIPAA Business Associate Agreement training and HIPAA Security training. Training is refreshed as the rules and our work change.

Breach notification

If PHI in our care is ever breached, we notify the affected covered entity without unreasonable delay and within the timeframe the HIPAA Breach Notification Rule and our BAA require, and we support that customer's own notification obligations.

What this page does and does not cover

HIPAA governs the protected health information a covered entity entrusts to us. It does not govern ordinary account or product information, which is covered by our Privacy Policy. Where both apply, the BAA controls the handling of PHI.

Questions

For a BAA, a security review, or a copy of our safeguards documentation, email support [at] bwenzi.com.