Trust & Security
What happens to your patients' information once it is in Homeostasis: our position under HIPAA, the safeguards behind it, every subprocessor that touches data, and how to get the paperwork your compliance officer needs.
1. Our position under HIPAA
When your clinic uses Homeostasis for its patients, your clinic is the covered entity and Titra Health LLC is your Business Associate. We sign a Business Associate Agreement with every clinic before any patient data flows, and every subprocessor of ours that can touch PHI has signed a BAA with us.
We handle PHI only to perform the service, only as the BAA permits, and only as you instruct. We do not use it for our own marketing, we do not sell it, and we do not let it train anyone's models.
There is no such thing as being "HIPAA certified" — no government body issues such a certificate, and any vendor who says otherwise is telling you something that does not exist. What we can show you is the real thing: executed agreements, a documented risk analysis, named Security and Privacy Officers, written policies, and the technical controls described below. Ask for them and we will send them.
2. How access works
The access model is deliberately narrow, because the safest design is one where a broad disclosure is not possible in the first place.
- A clinic sees only its own patients. Access is scoped to patients linked to that clinic. There is no shared pool and no cross-clinic view.
- A patient sees only their own record, enforced in the database rather than in application code.
- The patient account exists before the patient does. Your staff provision it from the chart; the patient claims it with an eight-character code and their date of birth. The code alone is not sufficient.
- We read your medical record; we do not write to it. The EMR connection is read-only. Nothing the app or a patient does alters your chart. A clinician decides what, if anything, is carried across.
- Your clinic controls its own user list — who holds a dashboard account, and removing them when they leave.
- Sessions on shared hardware lock and time out, so the exam-room tablet does not leave the last patient's record open for the next person.
3. Technical safeguards
| Control | How it is implemented |
|---|---|
| Encryption in transit | TLS 1.2 or better on every connection, including between our services and every subprocessor. |
| Encryption at rest | AES-256 for the database, file storage and backups. |
| On-device encryption | Session tokens and cached clinical data on the patient's phone are encrypted with a device-bound key held in secure hardware (Keychain / Keystore). |
| Tenant isolation | Row-level security on every table, enforced by the database. A query that forgets a filter returns nothing rather than someone else's record. |
| Private file storage | Photographs and generated documents live in non-public buckets, scoped to the owning account, reached only by short-lived signed URLs. |
| Credential handling | No provider keys or service credentials in the mobile app. Privileged calls go through our server-side functions. |
| Authentication | Clinic-provisioned patient accounts have no password to phish or reuse. Dashboard accounts use authenticated sessions with leaked-password protection and short-lived tokens. |
| Least privilege | Staff access is scoped by clinic and by role. Access to production by our own personnel is limited, logged and reviewed. |
| Data minimisation | Identifiers are stripped before data reaches any AI provider; analytics identify by opaque ID only; notification text carries no clinical detail. |
Scroll the table sideways to see every column →
4. Audit and accounting
HIPAA §164.312(b) requires records of activity in systems holding PHI. Ours cover:
- Writes to clinical records — logged at the database level across the clinical tables, capturing who and when.
- Staff access to a patient record — logged on the dashboard.
- Every view of a patient photograph — logged individually: which photograph, which staff member, from where, and when.
- Disclosures — recorded so we can support your accounting-of-disclosures obligation under §164.528.
- AI activity — recorded as metadata only. We deliberately do not store the question, the answer or the payload.
Audit records are kept for six years and survive account deletion, as HIPAA requires. They record that an access happened; they do not retain clinical content.
5. AI and PHI
Our AI Policy is the full account. For a compliance review, the load-bearing facts:
- OpenAI is our only model provider, under a signed BAA with zero data retention — prompts and completions are not persisted after the request.
- No data is used for model training, by us or by any provider.
- Direct identifiers — name, date of birth, email, account ID, clinic code — are stripped before the request leaves our servers.
- Patient consent is enforced server-side on every request, not merely in the app's interface.
- The AI makes no clinical decision, writes nothing to your chart, and triggers no automated clinical action.
- Your chart data, patient photographs, and patient–clinic messages are never sent to an AI provider.
6. Subprocessors
The complete list of third parties that process data on our behalf. We keep it here so it can be checked rather than requested.
| Subprocessor | Function | Data processed | Location | BAA |
|---|---|---|---|---|
| Supabase | Database, authentication, file storage, serverless functions | All patient records and files | United States | Signed |
| Amazon Web Services | Underlying infrastructure for Supabase | All patient records and files, encrypted | United States | Via Supabase |
| OpenAI | AI features | De-identified clinical context, meal photographs, voice audio | United States | Signed, zero retention |
| PostHog | Product analytics, session replay | Usage events under an opaque ID; inputs and images masked on-device before transmission | United States | Signed |
| Sentry | Crash and error reporting | Stack traces, device and OS data, opaque user ID | United States | Signed |
| Expo | App delivery, over-the-air updates, push notifications | Push token, app version, notification text (no clinical detail) | United States | Not applicable |
| FatSecret | Food and nutrition database | Food search terms and barcode numbers only | United States | No PHI |
| Apple / Google | App distribution, on-device health data, push transport | Conduit only | United States | Conduit |
Scroll the table sideways to see every column →
On push notifications. Push traffic traverses Apple's and Google's networks, which no vendor can place under a BAA — a claim to the contrary should make you suspicious of the vendor making it. We address it by design instead: notification bodies carry no clinical detail. A reminder says it is time to log; it does not name a medication, a dose or a result.
We will give clinics notice before adding a subprocessor that would handle PHI, and this page is updated whenever the list changes.
7. Retention and destruction
- Active patients: records are retained while the account is active and the clinic relationship continues.
- Patient-initiated deletion: profile, logs, conversations, photographs and stored files are purged within 30 days — including objects in file storage, not only database rows.
- Generated documents are purged on a schedule rather than accumulating; share links are short-lived and revocable.
- Caches are pruned automatically.
- Audit and disclosure logs are retained six years per HIPAA, and are excluded from deletion by design.
- On termination: at your instruction we return or destroy the PHI we hold for you, subject to the audit-log retention above, and certify what was done.
Deleting a Homeostasis account never touches your clinic's own medical record. That remains yours, under your retention schedule.
8. Breach notification
If we discover a breach of unsecured PHI, we notify the affected clinic without unreasonable delay and no later than 60 days from discovery, per §164.410. Our notice identifies the patients involved, what happened, when, what information was affected, what we have done, and what we recommend — everything you need for your own notification obligations.
For direct consumer users, we follow the FTC Health Breach Notification Rule and applicable state breach laws.
We maintain a written incident response plan and test it. It is part of the documentation package below.
9. Patient rights requests
Where we act as your Business Associate, patient rights under HIPAA run through your clinic, not through us. That is the correct routing, and it is what we tell patients.
If a patient contacts us directly, we do not act on the request ourselves — we direct them to you and tell you it happened. When you need our help to answer one, we support access, amendment and accounting-of-disclosures requests within 15 days of your asking, so you have time inside HIPAA's 30-day window.
10. Reporting a vulnerability
If you believe you have found a security vulnerability, email support@titrahealth.io with "Security" in the subject line. Tell us what you found and how to reproduce it.
We will acknowledge within two business days and keep you updated until it is resolved. We will not pursue legal action against anyone who reports in good faith, acts only against their own account or test data, does not access or modify another person's information, and gives us a reasonable window before disclosing publicly.
11. Requesting the package
For a vendor security review or a compliance file, we can provide:
- Our Business Associate Agreement
- Security Risk Analysis (§164.308(a)(1))
- Incident response and breach notification procedures
- Access control, retention and destruction policies
- Encryption attestation
- Named Security Officer and Privacy Officer
- Workforce training and sanction policy
- Contingency and backup plan
- Subprocessor list with executed BAAs
- A completed security questionnaire in your own format
Email support@titrahealth.io and say which you need. We would rather send it before you ask twice.
Reviewing us as a vendor?
Send your questionnaire and we will complete it. If your compliance officer wants a call with the person who built this, that can be arranged too.
Email support@titrahealth.io