Security & Trust
Built for the systems that hold sensitive data.
Amesite runs HIPAA-compliant AI infrastructure. Sensitive data stays where it belongs; only what is needed moves, and only in one direction.
HIPAA-compliant infrastructure
The controls that run under every solution.
- Access control — zero-trust identity and provisioning.
- Encryption — at rest and in transit, with managed keys.
- De-identification — applied before any aggregate leaves the operator plane; small cells suppressed.
- PHI stays out of training — customer PHI is excluded from model training.
- Monitored threat surface — defended and monitored continuously.
- Kept current — maintained as component versions, endpoints, and regulations change.
Business Associate Agreements
We sign a BAA and handle PHI on your behalf.
Amesite enters a Business Associate Agreement with the covered entity and handles protected health information under it — for organizations and for individual providers alike.
Each agreement is published in full on NurseMagic — read the one that matches how you license Amesite.
Privacy by architecture
PHI stays in the operator plane. Only de-identified aggregates flow — one way.
Operator plane
System of record — unchanged.
Aggregate & owner view
PHI is excluded from training, and the overlay leaves your systems of record intact.
How we handle risk
We surface documentation risk and route it for review.
At the point of entry, the system checks each record against its required elements: the complete elements are confirmed, and the exceptions are flagged and routed to a person. We identify what to review and route it — the record, and the decision, stay with you.