HIPAA Compliance Statement
Last updated: August 21, 2026
Compliance Status: Designated HIPAA-Compliant Architecture
HormoneSync AI is built on HIPAA-compliant infrastructure and follows the administrative, physical, and technical safeguard requirements of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule (45 CFR Part 160 and Part 164, Subparts A and C). We treat all user health data as Protected Health Information (PHI) regardless of whether a formal BAA is in place.
1. What is HIPAA and Why Does It Matter?
HIPAA (Health Insurance Portability and Accountability Act of 1996) is a United States federal law that establishes national standards for the protection of sensitive patient health information. The HIPAA Security Rule requires covered entities and their business associates to implement administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI). HormoneSync AI handles sensitive health data including menstrual cycle information, symptom tracking, health conditions, lab results, and wearable biometric data. We have designed our entire platform to meet or exceed HIPAA requirements to protect this sensitive information.
2. Important: AI-Generated Content and HIPAA
AI Processing Notice
HormoneSync AI uses artificial intelligence models to process your health data and generate personalized recommendations. These AI models operate within our HIPAA-compliant infrastructure. However, you must understand that:
- AI-generated health recommendations are for educational purposes only and do not constitute medical advice.
- AI processing of your health data is conducted with the same security standards as all other PHI handling.
- AI model outputs may contain inaccuracies and should always be reviewed by a qualified healthcare professional.
- Our AI models are not certified as medical devices by any regulatory authority.
3. Administrative Safeguards
- Designated Security Officer: We have appointed a Chief Information Security Officer (CISO) responsible for developing and implementing security policies and procedures.
- Workforce Training: All employees and contractors with access to PHI complete mandatory HIPAA training upon hiring and annually thereafter. Training covers security awareness, data handling procedures, breach notification protocols, and social engineering prevention.
- Access Management: Role-based access control (RBAC) ensures that only authorized personnel with a documented business need can access PHI. Access is granted on a least-privilege basis and is regularly audited.
- Security Risk Assessment: We conduct comprehensive security risk assessments annually, as required by HIPAA, identifying potential threats and vulnerabilities to ePHI and implementing corrective actions.
- Incident Response Plan: A documented incident response plan is maintained and tested regularly. This includes procedures for identifying, containing, and mitigating security incidents, as well as breach notification procedures compliant with the HIPAA Breach Notification Rule.
- Business Associate Agreements (BAAs): We execute BAAs with all third-party vendors and service providers who may access, process, or store PHI on our behalf, including cloud infrastructure providers and payment processors.
- Contingency Plan: We maintain a comprehensive contingency plan including data backup, disaster recovery, and emergency mode operation procedures. Backups are encrypted and tested regularly.
4. Physical Safeguards
- Cloud-First Architecture: Our infrastructure is hosted on HIPAA-compliant cloud platforms (SOC 2 Type II certified) with physical security controls including 24/7 security personnel, biometric access controls, video surveillance, and environmental controls (fire suppression, climate control, UPS, generator backup).
- Workstation Security: Company-issued devices are encrypted, have screen lock enabled, and are managed through mobile device management (MDM) software.
- Device and Media Controls: Proper procedures for the disposal and reuse of electronic media containing ePHI are followed, including cryptographic erasure or physical destruction.
5. Technical Safeguards
- AES-256 Encryption at Rest: All data stored in our databases, backups, and file systems is encrypted using AES-256-bit encryption.
- TLS 1.3 in Transit: All data transmitted between your device and our servers is encrypted using TLS 1.3 with strong cipher suites.
- Authentication: Multi-factor authentication (MFA) is available and recommended for all user accounts. API authentication uses secure token-based mechanisms.
- Access Logging: Comprehensive audit logs record all access to, modification of, and deletion of ePHI. Logs are protected from tampering and retained for a minimum of 6 years.
- Encryption Key Management: Encryption keys are managed through a dedicated key management service (KMS) with automatic key rotation. Keys are stored separately from encrypted data.
- Network Security: Infrastructure is protected by firewalls, intrusion detection/prevention systems (IDS/IPS), and web application firewalls (WAF). Regular vulnerability scanning and penetration testing are conducted by third-party security firms.
- Session Management: Secure session handling with automatic timeout, session invalidation on logout, and protection against session fixation and hijacking.
- Input Validation: All user inputs are validated and sanitized to prevent injection attacks (SQL injection, XSS, CSRF).
- Vulnerability Management: Automated dependency scanning and manual code reviews are part of our development process. Critical vulnerabilities are patched within 24 hours.
6. Your Rights Under HIPAA
As a user of HormoneSync AI, you have the following rights regarding your Protected Health Information:
- Right to Access: You may request a copy of your PHI in electronic or paper format.
- Right to Amend: You may request corrections to your PHI that you believe is inaccurate or incomplete.
- Right to an Accounting of Disclosures: You may request a record of certain disclosures of your PHI made by us.
- Right to Request Restrictions: You may request restrictions on certain uses and disclosures of your PHI.
- Right to Confidential Communications: You may request that we communicate with you about your PHI in a certain way or at a certain location.
- Right to a Paper Copy of This Notice: You may obtain a paper copy of our HIPAA compliance notice at any time.
- Right to Be Notified of a Breach: You will be notified without unreasonable delay (and no later than 60 days) if there is a breach of your unsecured PHI.
7. Breach Notification
In the event of a breach of unsecured PHI, HormoneSync AI will notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery of the breach, as required by the HIPAA Breach Notification Rule. Notification will be provided by first-class mail to the last known address, or by email if the individual has agreed to electronic notification. If the breach affects more than 500 individuals in a state or jurisdiction, we will also notify prominent media outlets serving that area and the HHS Secretary. We will document all breach investigations and notifications.
8. Compliance Certifications
9. Contact for HIPAA Concerns
If you have questions about our HIPAA compliance, believe your PHI has been compromised, or wish to exercise any of your HIPAA rights, please contact us:
- Privacy Officer: privacy@cyclesyncai.com
- Security Officer: security@cyclesyncai.com
- General Inquiries: support@cyclesyncai.com
You also have the right to file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights if you believe your HIPAA rights have been violated.