# HIPAA (frontend)

<div><figure><img src="/files/BVZcKaEIH5fFaJiyZ7PO" alt=""><figcaption></figcaption></figure> <figure><img src="/files/IH349tpPHMwGACk4gHsD" alt="" width="320"><figcaption></figcaption></figure> <figure><img src="/files/v1gDkqrpHzWLrM9gcdhQ" alt=""><figcaption></figcaption></figure></div>

## ⚡100%. *<mark style="color:purple;">**Private**</mark>*. Network.

{% content-ref url="/pages/R8Tnf6QtiYmKdht7P7fQ" %}
[Private Network](/lisaiceland/privacy+/private-network.md)
{% endcontent-ref %}

{% content-ref url="/pages/H5L4SlZuxVJvnS8az15Y" %}
[Security+](/lisaiceland/platform+/security+.md)
{% endcontent-ref %}

{% content-ref url="/pages/8legEWsPMN02YRpNVJ8b" %}
[Privacy+](/lisaiceland/privacy+.md)
{% endcontent-ref %}

## ⚡*<mark style="color:red;">**100%**</mark>*. Compliant. *<mark style="color:purple;">**Frontend**</mark>*.

<figure><img src="/files/58kDUhqnpYedWt18KBxg" alt=""><figcaption></figcaption></figure>

### **HIPAA** Compliance&#x20;

* Industry-standard certifications for our frontend infrastructure includes HIPAA, AICPA SOC 2 Type 2, ISO 27001, ISO 27018, and PCI DSS v4.0.&#x20;
* Our security & privacy-first approach ensures that ALL our web applications not only meet regulatory requirements but also maintain the highest standards of data protection.

### **Advanced** Security Measures <a href="#advanced-security-measures-for-peace-of-mind" id="advanced-security-measures-for-peace-of-mind"></a>

* Our HIPAA service offering on the frontend integrates & builds on the robust security measures already embedded in our backend platform.&#x20;
* It's ***100% End-to-End***.&#x20;
* It has undergone additional, rigorous audits to ensure full compliance with healthcare data regulations.&#x20;

### **Key Security** Features

* *<mark style="color:purple;">**End-to-End**</mark>* *<mark style="color:purple;">Encryption</mark>*
  * Ensuring all data is encrypted both in transit and at rest.
* <mark style="color:purple;">**Vulnerability**</mark> *<mark style="color:purple;">& Patch Management</mark>*
  * Regular internal and third-party penetration testing, alongside ongoing patch management, to identify, mitigate, and address potential security risks.
* *<mark style="color:purple;">**Access**</mark>* *<mark style="color:purple;">Control</mark>*
  * Strict control mechanisms to ensure that only authorized personnel can access sensitive data.
* *<mark style="color:purple;">**Your**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Business</mark>*
  * HIPAA promotes the use of electronic health records while safeguarding the security and privacy of PHI. For healthcare providers and businesses handling PHI, compliance with HIPAA is not just a regulatory obligation but a crucial component of maintaining trust with patients and clients.
  * We are considered a business associate (BA) for our healthcare customers, who must comply with HIPAA. With this announcement of HIPAA compliance, any/all customers handling PHI can now execute a Business Associates Agreement (BAA) with us.
* *<mark style="color:purple;">**Secure**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Architecture</mark>*
  * Security in the cloud is a shared responsibility—one we don’t take lightly. To make it easier, we’ve created secure reference architectures to assist customers who must meet regulatory or special data processing requirements in the healthcare space and beyond.
* *<mark style="color:purple;">**Tight**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Security</mark>*&#x20;
  * Hardware-level
  * Software-level
  * Cloud-functions-level
  * Middleware-level
  * PII & PHI *<mark style="color:purple;">**"in-chat"**</mark>*
* *<mark style="color:purple;">**Privacy-First**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">& AI-Safety Compliance</mark>*
  * *<mark style="color:purple;">**LLM Safety**</mark>*
  * *<mark style="color:purple;">**AI Gateway**</mark>*
  * *<mark style="color:purple;">**Datacenter**</mark>*
* *<mark style="color:purple;">**Beyond**</mark>* *<mark style="color:purple;">AI</mark>*&#x20;
  * Security *<mark style="color:purple;">**Guardrails**</mark>*
  * *<mark style="color:purple;">**Bias**</mark>* Protections
* *<mark style="color:purple;">**Extra**</mark>* Compliance
  * PCI DSS, SOC2 Type II, GDPR
* *<mark style="color:purple;">**Secure**</mark> AI*&#x20;
  * In-Depth monitoring&#x20;
  * Retry logic built-in
* *<mark style="color:purple;">**Secure**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Credential Storage</mark>*
  * We securely store credentials like API keys and access tokens necessary to connect with third-party services. These are encrypted and accessible only to the our systems that need them to operate the service.
* *<mark style="color:purple;">**Data**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Minimization</mark>*
  * We implement data minimization practices to only collect and process the data needed for the service.
* *<mark style="color:purple;">**Data**</mark> <mark style="color:purple;"></mark><mark style="color:purple;">Tunneling</mark>*
  * We tunnel data securely end-to-end by enforcing **HTTPS/TLS encryption** for all traffic, protecting data in transit with strong ciphers like AES-256, and isolating sensitive operations (like serverless functions) in temporary, secure environments, preventing data leakage.&#x20;
  * Key features include automatic SSL, DDoS mitigation, and built-in secret management (Secrets Controller) to prevent exposing API keys, ensuring data remains encrypted from client to edge, i.e. our frontend to our backend infrastructure, through functions, and to our external backend services.&#x20;
* *<mark style="color:purple;">**Limited**</mark>* *<mark style="color:purple;">& NO Access</mark>*
  * Only authorized systems, API & any other internal admins&#x20;
  * Limited to 2 at a time and rotated every week
  * We always us store & de-identify (aka data masking or deID) credentials.

{% embed url="<https://www.netlify.com/blog/netlify-launches-a-hipaa-compliant-service-offering/>" %}

{% embed url="<https://www.netlify.com/security/>" %}

## ⚡Compliant. <mark style="color:green;">GREEN</mark>. *<mark style="color:purple;">**Backend**</mark>*.

{% content-ref url="/pages/pD0nMCoibNNyguZMv5LF" %}
[Compliant LLM Gateway](/lisaiceland/platform+/subprocessors/compliant-llm-gateway.md)
{% endcontent-ref %}

## ⚡*<mark style="color:purple;">**BAA**</mark>*. Execute. *<mark style="color:purple;">Now</mark>*.

{% content-ref url="/pages/ZdiLlpsvZKtmZRfhWQ3v" %}
[BAA](/lisaiceland/privacy+/hipaa-or-soc2-or-pci/hipaa/baa.md)
{% endcontent-ref %}

* For ALL client entities
* BAA sample fill 100% online...
* Edit, Save & Print
* Email us & we'll e-sign it at:
  * <support@lisaiceland.com>

{% content-ref url="/pages/ZdiLlpsvZKtmZRfhWQ3v" %}
[BAA](/lisaiceland/privacy+/hipaa-or-soc2-or-pci/hipaa/baa.md)
{% endcontent-ref %}

<div data-full-width="true"><figure><img src="/files/y7x48ro0w1dLjws2sO44" alt=""><figcaption></figcaption></figure></div>

{% content-ref url="/pages/rtds6tbaoVi419LaqToL" %}
[💲 Affiliates+ = Earn 40%💲](/lisaiceland/affiliates+-earn-40.md)
{% endcontent-ref %}

<div data-full-width="true"><figure><img src="/files/qRvnYj9bNHzZa9TSRMQ2" alt=""><figcaption></figcaption></figure></div>

<div data-full-width="true"><figure><img src="/files/IiXM8QrjUsHjDTzlT2oe" alt="" width="207"><figcaption></figcaption></figure> <figure><img src="/files/hxhZTa9jV9RhDURTQ1cV" alt="" width="128"><figcaption></figcaption></figure></div>

<div data-full-width="true"><figure><img src="/files/jJtx8moQrUSFSd38FdUs" alt=""><figcaption></figcaption></figure></div>

{% embed url="<https://donate.doctorswithoutborders.org/secure/help-save-lives-oct-rr-paid?gclid=CjwKCAjw1t2pBhAFEiwA_-A-NGX60xMDYBu6hI0Fq9YE-8VCGjBJCB873G31hXSfpSiheFvYDQtsyhoCVtUQAvD_BwE&ms=ADD2310U1U76&utm_campaign=NONBRAND_CKMSF-NONBRAND-GS-GS-ALL-GazaRR.Exact-BO-ALL-RSA-GazaSupportRR23-ONETIME&utm_medium=cpc&utm_source=google>" %}

<figure><img src="/files/c5ADWjVOmud05Se5FuAx" alt="" width="100"><figcaption></figcaption></figure>

<figure><img src="/files/81jjaVZJiHpllHaEwdyr" alt=""><figcaption></figcaption></figure>


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://nexas-ridewiz.gitbook.io/lisaiceland/privacy+/hipaa-or-soc2-or-pci/hipaa/hipaa-frontend.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
