Security & Compliance

How Akeso AI protects protected health information

Written for practice managers, clinical IT leads and compliance officers evaluating Akeso AI. Everything below reflects controls implemented in the platform today, with our Business Associate Agreement terms published in full.

HIPAA Security Rule alignedSigned BAA with every clinicUS-only data residencyZero retention AI

Administrative, physical and technical safeguards

Encryption everywhere

TLS 1.3 in transit and AES-256 at rest for every document, appeal package and audit record. Storage buckets are private with signed, short-lived access URLs.

Client-side PHI redaction

Names, MRNs, dates of birth and contact details are tokenized in the browser before any document leaves the practice network.

Zero data retention inference

Clinical inference runs under a zero-retention configuration. Prompts and completions are not stored or used for model training.

Immutable audit ledger

Every PHI view, export, upload, generation and transmission is appended to a ledger where database triggers reject updates and deletes. Six-year retention.

15-minute workstation lock

Idle sessions lock automatically with a 60-second warning and require password re-entry, satisfying the HIPAA workstation-use safeguard.

Least-privilege RBAC

Five staff roles scoped per clinic and enforced with database row-level security so staff only reach their own practice's records.

Where patient data travels

A denial letter enters the platform through the clinic browser and never reaches an inference provider with direct identifiers attached.

Step 1

Clinic browser

Upload + client-side PHI tokenization

Step 2

Encrypted transit

TLS 1.3 to US application tier

Step 3

Private storage

AES-256 buckets, signed URLs, RLS

Step 4

Zero-retention AI

De-identified tokens only

Step 5

Audit ledger

Append-only, six-year retention

Platform controls

Role-Based Access Control (RBAC)

Five staff roles — Practice Admin, Prescribing Physician, PA Coordinator, Billing/Finance and Read Only — each with least-privilege access enforced in the database, not just the interface.

Immutable WORM Audit Logging

Every PHI view, export, upload, appeal generation, fax dispatch and settings change is appended to a ledger with database triggers blocking updates and deletes. Six-year retention.

Session Guard

A 60-second warning at 14 minutes of inactivity, then a full-screen frosted workstation lock at 15 minutes requiring password re-entry. Unsaved case work is preserved.

Disaster Recovery

Automated point-in-time database backups with geo-redundant storage and documented restore drills.

Subprocessors

Every subprocessor that may process PHI on our behalf, with an executed BAA on file.

VendorPurposeData touchedBAARegion
Akeso AI clinical inference (HIPAA-eligible cloud)Clinical extraction and appeal drafting under signed BAADe-identified clinical tokensExecuted — zero data retentionUnited States
Akeso AI managed cloud platformPostgreSQL database, authentication and encrypted document storageCase metadata, encrypted chart documentsExecutedUnited States
TwilioHIPAA-eligible SMS and voice carrier servicesHashed phone identifiers, status-only message bodiesExecutedUnited States

Business Associate Agreement

Version AKESO-BAA-2026.1. Executed electronically by an authorized representative during clinic onboarding.

Published in full

Reporting a vulnerability

Email security@akesohealth.com with reproduction steps. We acknowledge reports within one business day and will not pursue legal action for good-faith research that avoids accessing real patient data.

Start a clinic workspace