HIPAA compliance
PostureAI serves Covered Entities as a Business Associate. Here is exactly how we meet the Privacy, Security, and Breach Notification Rules.
Technical safeguards
- AES-256 encryption at rest (AWS KMS-managed keys)
- TLS 1.2+ for all data in transit
- Append-only, tamper-evident audit log
- 15-minute idle session timeout
- MFA supported on all accounts
Administrative safeguards
- Annual workforce security training
- Role-based access control with least privilege
- Documented incident response plan
- Annual risk assessment
- Sanctions policy for workforce violations
Physical safeguards
- AWS-hosted infrastructure (BAA available via AWS Artifact)
- No physical PHI storage by PostureAI
- Workstation and media-disposal policies for staff
Audit and accountability
- Append-only, tamper-evident audit log of all PHI access
- Six-year log retention (HIPAA minimum)
- Log exports available to customers on request
Business Associate Agreement
We sign our standard BAA with every Covered Entity customer at no additional cost. It follows HHS model language and includes breach notification timelines, minimum-necessary use commitments, sub-processor pass-through, and data return or destruction obligations.
To request our BAA template in advance of signup, email security@posturegrade.com.
Breach notification
If PostureAI discovers a breach of unsecured PHI, we notify affected Covered Entity customers without unreasonable delay and in any case within 60 days of discovery, per the Breach Notification Rule.
Sub-processors
A current list of sub-processors who may encounter PHI, and the BAA status of each, is maintained and shared on request.