Protecting PHI at Every Step
A plain-English look at how SynapChart handles Protected Health Information: what it is, where it lives, who can see it, and how long we keep it.
What Counts as PHI
Protected Health Information (PHI) includes any individually identifiable health data you submit to SynapChart: patient names, dates of birth, medical record numbers, chart notes, lab values, images of documents, and any clinical detail tied to an identifiable individual. We treat everything you upload as PHI by default.
Encryption at Rest and in Transit
All PHI is encrypted in transit with TLS 1.3 and at rest with AES-256. Encryption keys are managed by a dedicated key management service with automatic rotation. Backups are encrypted with independent keys and stored in isolated, access-controlled environments.
HIPAA Compliance & BAAs
SynapChart operates as a Business Associate under HIPAA. We sign a Business Associate Agreement (BAA) with every covered entity customer before any PHI is transmitted. Every subprocessor that could touch PHI (cloud hosting, database, AI inference) is also under a BAA with us.
Minimum Necessary Access
PHI access follows the HIPAA minimum necessary standard. Role-based access control, MFA, and just-in-time elevation gate every internal action. No SynapChart employee can access customer PHI without an approved support ticket and audit-logged justification.
Audit Logging & Monitoring
Every read, write, and export of PHI is written to an immutable audit log retained for at least six years, satisfying the HIPAA Security Rule. Anomalous access patterns trigger automated alerts to our security team 24/7.
Where Your Data Lives
PHI is processed and stored on HIPAA-eligible U.S. cloud infrastructure with network isolation, private subnets, and continuous vulnerability scanning. Data does not leave the United States. Data is never used to train third-party AI models.
Retention & Deletion
Uploaded charts and images are purged within 30 days of processing unless your workflow explicitly requires longer retention. You can request full deletion of your organization's PHI at any time and we complete the request within 30 days, with a signed certificate of destruction on request.
Breach Notification
In the unlikely event of a breach involving PHI, we notify affected customers without unreasonable delay and in no case later than the HIPAA-mandated 60-day window. Our internal target is notification within 24 hours of confirmed impact.
Need a signed BAA, a subprocessor list, or documentation for your security review? Our team responds within one business day.
Request Compliance Documentation