Bridge MD AI is purpose-built for specialty medical practices. This page explains how we approach HIPAA compliance, protect Protected Health Information (PHI), and fulfill our obligations as your Business Associate.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA), along with its implementing regulations under 45 CFR Parts 160 and 164, establishes national standards for the protection of individuals' medical records and other identifiable health information.
HIPAA includes three key rules relevant to our platform:
Under HIPAA, a Business Associate is any entity that creates, receives, maintains, or transmits PHI on behalf of a Covered Entity to perform a service. Bridge MD AI qualifies as a Business Associate because our platform processes patient referral documents, clinical records, and other PHI as part of delivering our services to your practice.
As your Business Associate, we are directly subject to HIPAA's Security Rule requirements and the applicable provisions of the Privacy Rule. This means we are legally obligated — not just contractually — to protect the PHI we handle.
A Business Associate Agreement (BAA) must be executed before any PHI is transmitted through Bridge MD AI. We will not knowingly accept PHI without a signed BAA in place.
A Business Associate Agreement is a written contract required by HIPAA that defines how PHI may be used and disclosed by Bridge MD AI on your behalf, and establishes the safeguards we agree to maintain.
Our BAA covers:
To request a BAA or ask questions about our agreement, contact us at hello@bridgemdai.com.
Protected Health Information (PHI) is any individually identifiable health information that is created, received, maintained, or transmitted by a Covered Entity or Business Associate. This includes information related to:
PHI includes 18 HIPAA-defined identifiers such as name, date of birth, address, phone number, Social Security number, medical record number, health plan beneficiary number, and more — even when they appear in faxes, referral documents, or clinical notes.
Do not transmit PHI through our public website contact form. PHI should only be transmitted through your provisioned Bridge MD AI platform environment after your BAA is signed and your secure channels are configured.
Bridge MD AI uses and discloses PHI only as permitted under your BAA and HIPAA. Specifically:
We apply the Minimum Necessary Standard — we access only the PHI required to perform the specific task at hand, and we do not use PHI for marketing, advertising, or any purpose beyond delivering contracted services.
We implement technical controls designed to protect electronic PHI (ePHI) in accordance with the HIPAA Security Rule:
All ePHI is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256.
Role-based access with unique user IDs, least-privilege permissions, and session timeouts.
Immutable audit trails record all access to and modifications of PHI with timestamps and user attribution.
Inactive sessions are automatically terminated to prevent unauthorized access to unattended workstations.
Mechanisms to detect unauthorized alteration or destruction of ePHI during storage and transmission.
Secure network protocols and certificate-based authentication prevent interception of data in transit.
Administrative safeguards are the policies and procedures that govern how we manage PHI across our organization:
Physical safeguards protect the physical systems and locations where ePHI is stored or accessed:
In the event of a suspected or confirmed breach of unsecured PHI, Bridge MD AI will:
As the Covered Entity, your practice is responsible for notifying affected individuals and HHS. Bridge MD AI will provide all documentation and support needed to complete those notifications.
To report a potential security incident, contact us immediately at hello@bridgemdai.com with "SECURITY INCIDENT" in the subject line.
While Bridge MD AI maintains robust safeguards as your Business Associate, your practice retains certain responsibilities under HIPAA:
HIPAA grants patients specific rights regarding their health information. As a Business Associate, Bridge MD AI supports your practice in honoring these rights. Patients have the right to:
Patient rights requests should be directed to your practice. Bridge MD AI will assist your team in locating and producing relevant records from our platform when needed.
For all HIPAA-related inquiries including BAA requests, compliance questions, security incidents, or patient rights support, contact us at:
Our team can help with Business Associate Agreement requests, compliance questions, and secure onboarding guidance for your practice.
Request HIPAA / BAA SupportRequired for core site functionality, security, and session integrity. These cannot be disabled.
Help us understand site performance — pages visited, session duration, and traffic sources. No patient data involved.
Used for advertising tracking and cross-site activity. We recommend keeping this off for healthcare-related contexts.
You can update these preferences at any time using the "Cookie Settings" link in the footer.