For clinics

Trust & Security

What happens to your patients' information once it is in Homeostasis: our position under HIPAA, the safeguards behind it, every subprocessor that touches data, and how to get the paperwork your compliance officer needs.

Last reviewed 13 September 2026Titra Health LLC d/b/a Homeostasis

1. Our position under HIPAA

When your clinic uses Homeostasis for its patients, your clinic is the covered entity and Titra Health LLC is your Business Associate. We sign a Business Associate Agreement with every clinic before any patient data flows, and every subprocessor of ours that can touch PHI has signed a BAA with us.

We handle PHI only to perform the service, only as the BAA permits, and only as you instruct. We do not use it for our own marketing, we do not sell it, and we do not let it train anyone's models.

What we do not claim

There is no such thing as being "HIPAA certified" — no government body issues such a certificate, and any vendor who says otherwise is telling you something that does not exist. What we can show you is the real thing: executed agreements, a documented risk analysis, named Security and Privacy Officers, written policies, and the technical controls described below. Ask for them and we will send them.

2. How access works

The access model is deliberately narrow, because the safest design is one where a broad disclosure is not possible in the first place.

  • A clinic sees only its own patients. Access is scoped to patients linked to that clinic. There is no shared pool and no cross-clinic view.
  • A patient sees only their own record, enforced in the database rather than in application code.
  • The patient account exists before the patient does. Your staff provision it from the chart; the patient claims it with an eight-character code and their date of birth. The code alone is not sufficient.
  • We read your medical record; we do not write to it. The EMR connection is read-only. Nothing the app or a patient does alters your chart. A clinician decides what, if anything, is carried across.
  • Your clinic controls its own user list — who holds a dashboard account, and removing them when they leave.
  • Sessions on shared hardware lock and time out, so the exam-room tablet does not leave the last patient's record open for the next person.

3. Technical safeguards

ControlHow it is implemented
Encryption in transitTLS 1.2 or better on every connection, including between our services and every subprocessor.
Encryption at restAES-256 for the database, file storage and backups.
On-device encryptionSession tokens and cached clinical data on the patient's phone are encrypted with a device-bound key held in secure hardware (Keychain / Keystore).
Tenant isolationRow-level security on every table, enforced by the database. A query that forgets a filter returns nothing rather than someone else's record.
Private file storagePhotographs and generated documents live in non-public buckets, scoped to the owning account, reached only by short-lived signed URLs.
Credential handlingNo provider keys or service credentials in the mobile app. Privileged calls go through our server-side functions.
AuthenticationClinic-provisioned patient accounts have no password to phish or reuse. Dashboard accounts use authenticated sessions with leaked-password protection and short-lived tokens.
Least privilegeStaff access is scoped by clinic and by role. Access to production by our own personnel is limited, logged and reviewed.
Data minimisationIdentifiers are stripped before data reaches any AI provider; analytics identify by opaque ID only; notification text carries no clinical detail.

Scroll the table sideways to see every column →

4. Audit and accounting

HIPAA §164.312(b) requires records of activity in systems holding PHI. Ours cover:

  • Writes to clinical records — logged at the database level across the clinical tables, capturing who and when.
  • Staff access to a patient record — logged on the dashboard.
  • Every view of a patient photograph — logged individually: which photograph, which staff member, from where, and when.
  • Disclosures — recorded so we can support your accounting-of-disclosures obligation under §164.528.
  • AI activity — recorded as metadata only. We deliberately do not store the question, the answer or the payload.

Audit records are kept for six years and survive account deletion, as HIPAA requires. They record that an access happened; they do not retain clinical content.

5. AI and PHI

Our AI Policy is the full account. For a compliance review, the load-bearing facts:

  • OpenAI is our only model provider, under a signed BAA with zero data retention — prompts and completions are not persisted after the request.
  • No data is used for model training, by us or by any provider.
  • Direct identifiers — name, date of birth, email, account ID, clinic code — are stripped before the request leaves our servers.
  • Patient consent is enforced server-side on every request, not merely in the app's interface.
  • The AI makes no clinical decision, writes nothing to your chart, and triggers no automated clinical action.
  • Your chart data, patient photographs, and patient–clinic messages are never sent to an AI provider.

6. Subprocessors

The complete list of third parties that process data on our behalf. We keep it here so it can be checked rather than requested.

SubprocessorFunctionData processedLocationBAA
SupabaseDatabase, authentication, file storage, serverless functionsAll patient records and filesUnited StatesSigned
Amazon Web ServicesUnderlying infrastructure for SupabaseAll patient records and files, encryptedUnited StatesVia Supabase
OpenAIAI featuresDe-identified clinical context, meal photographs, voice audioUnited StatesSigned, zero retention
PostHogProduct analytics, session replayUsage events under an opaque ID; inputs and images masked on-device before transmissionUnited StatesSigned
SentryCrash and error reportingStack traces, device and OS data, opaque user IDUnited StatesSigned
ExpoApp delivery, over-the-air updates, push notificationsPush token, app version, notification text (no clinical detail)United StatesNot applicable
FatSecretFood and nutrition databaseFood search terms and barcode numbers onlyUnited StatesNo PHI
Apple / GoogleApp distribution, on-device health data, push transportConduit onlyUnited StatesConduit

Scroll the table sideways to see every column →

On push notifications. Push traffic traverses Apple's and Google's networks, which no vendor can place under a BAA — a claim to the contrary should make you suspicious of the vendor making it. We address it by design instead: notification bodies carry no clinical detail. A reminder says it is time to log; it does not name a medication, a dose or a result.

We will give clinics notice before adding a subprocessor that would handle PHI, and this page is updated whenever the list changes.

7. Retention and destruction

  • Active patients: records are retained while the account is active and the clinic relationship continues.
  • Patient-initiated deletion: profile, logs, conversations, photographs and stored files are purged within 30 days — including objects in file storage, not only database rows.
  • Generated documents are purged on a schedule rather than accumulating; share links are short-lived and revocable.
  • Caches are pruned automatically.
  • Audit and disclosure logs are retained six years per HIPAA, and are excluded from deletion by design.
  • On termination: at your instruction we return or destroy the PHI we hold for you, subject to the audit-log retention above, and certify what was done.

Deleting a Homeostasis account never touches your clinic's own medical record. That remains yours, under your retention schedule.

8. Breach notification

If we discover a breach of unsecured PHI, we notify the affected clinic without unreasonable delay and no later than 60 days from discovery, per §164.410. Our notice identifies the patients involved, what happened, when, what information was affected, what we have done, and what we recommend — everything you need for your own notification obligations.

For direct consumer users, we follow the FTC Health Breach Notification Rule and applicable state breach laws.

We maintain a written incident response plan and test it. It is part of the documentation package below.

9. Patient rights requests

Where we act as your Business Associate, patient rights under HIPAA run through your clinic, not through us. That is the correct routing, and it is what we tell patients.

If a patient contacts us directly, we do not act on the request ourselves — we direct them to you and tell you it happened. When you need our help to answer one, we support access, amendment and accounting-of-disclosures requests within 15 days of your asking, so you have time inside HIPAA's 30-day window.

10. Reporting a vulnerability

If you believe you have found a security vulnerability, email support@titrahealth.io with "Security" in the subject line. Tell us what you found and how to reproduce it.

We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue legal action against anyone who reports in good faith, acts only against their own account or test data, does not access or modify another person's information, and gives us a reasonable window before disclosing publicly.

11. Requesting the package

For a vendor security review or a compliance file, we can provide:

  • Our Business Associate Agreement
  • Security Risk Analysis (§164.308(a)(1))
  • Incident response and breach notification procedures
  • Access control, retention and destruction policies
  • Encryption attestation
  • Named Security Officer and Privacy Officer
  • Workforce training and sanction policy
  • Contingency and backup plan
  • Subprocessor list with executed BAAs
  • A completed security questionnaire in your own format

Email support@titrahealth.io and say which you need. We would rather send it before you ask twice.

Reviewing us as a vendor?

Send your questionnaire and we will complete it. If your compliance officer wants a call with the person who built this, that can be arranged too.

Email support@titrahealth.io