CData Connect AI supports HIPAA-regulated workloads
CData Connect AI can be configured to support workloads involving protected health information (PHI). CData requires a Business Associate Agreement (BAA) for eligible use cases involving PHI.
Background
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) is a U.S. federal law that establishes privacy and security standards for protected health information (PHI). If your organization is a covered entity or business associate subject to HIPAA, CData Connect AI can be configured to support PHI within your data workflows.
When a covered entity or business associate has executed a BAA with CData, Connect AI is available for eligible HIPAA-regulated use cases and CData operates as a business associate.
Requirements and limitations
For eligible HIPAA-regulated use cases, CData offers a BAA.
Please note the following limitations:
- Do not use Connect AI to communicate with patients (or their personal representatives), plan members, or family members.
- Do not submit PHI as free-text input to AI prompts.
- Do not use support impersonation features when PHI may be involved.
- Do not use legacy OData endpoints for PHI workflows.
- Do not submit PHI through live chat, support chatbot, public email, or personal email.
The above limitations are not eligible use cases for PHI. CData does not support HIPAA compliance for such use cases.
If you enable query logging at verbosity level 3 or above, those logs may contain PHI and the BAA will apply to those logs.