Health Assistant

Important limits and safeguards

Health Information & HIPAA Notice

This notice explains when HIPAA may apply, what this service does not claim, and the safeguards required before regulated health information is used.

Effective date: September 21, 2026

1. No claim of HIPAA compliance

51Heal Health Assistant does not represent through this notice that the service, this deployment, or every connected provider is HIPAA compliant. HIPAA status depends on who operates the service, the relationships involved, executed agreements, technical configuration, policies, training, risk analysis, and ongoing operations.

2. When HIPAA applies

HIPAA generally applies to covered entities and their business associates, not automatically to every wellness application or every piece of health-related information. Information can become protected health information when it is created, received, maintained, or transmitted by a covered entity or business associate in a regulated context. Obtain qualified legal and compliance advice for the intended use.

3. Before regulated PHI is used

  • Execute required Business Associate Agreements with AWS, OpenAI, and every other provider that will create, receive, maintain, or transmit PHI.
  • Confirm that every product and feature used is covered by those agreements and is configured in accordance with them.
  • Complete and document a HIPAA security risk analysis and risk-management plan.
  • Implement access controls, audit logging, workforce training, incident response, retention, backup, recovery, and breach-notification procedures.
  • Have qualified healthcare/privacy counsel approve the final Privacy Policy, Terms, authorization flows, and operational practices.

4. Email limitation

Resend currently states that it is not HIPAA compliant and cannot sign a Business Associate Agreement. While Resend is configured, emails must remain generic and must not contain health records, chat text, attachments, diagnoses, medications, appointment details, or other regulated PHI. A HIPAA-eligible mail service under an applicable BAA should be used if PHI must be transmitted by email.

5. AWS storage and backups

Private Amazon S3 storage and encrypted backups can support a HIPAA-aligned architecture, but AWS eligibility alone is not compliance. If HIPAA applies, the AWS account must be covered by an AWS BAA and the bucket, IAM permissions, encryption, logging, versioning, lifecycle, and recovery controls must be approved and continuously maintained.

6. Medical and emergency notice

The service is not a healthcare provider and does not provide diagnosis or treatment. Never use it as an emergency service. Call local emergency services immediately if you believe someone may be in danger or experiencing a medical emergency.

7. Questions

For privacy questions or to report a suspected incident, contact privacy@51heal.com. Do not include health details in the subject line or initial email message.