Skip to main content

PHI Management

Atticus Health governs Protected Health Information across its full lifecycle — from collection through disposal — enforcing HIPAA's Privacy and Security Rules at every stage.

PHI Lifecycle

StageDescriptionDetails
CollectionPHI enters the platform through patient intake, clinical encounters, and integrationsAuthentication
ClassificationAll data is treated as PHI by default — full encryption, access control, and audit logging apply universallyData Protection
StoragePHI is encrypted at rest with AES-256 and isolated per organizationEncryption
AccessRole-based access levels enforce least-privilege across all user typesAccess Levels
SharingExternal data exchange flows through authenticated APIs and FHIRThird-Party Data Sharing
RetentionClinical records retained 7 years minimum; retention enforced automaticallyRetention Policies
DisposalVerified deletion workflows with audit trail upon offboardingData Portability

Minimum Necessary Standard

Atticus Health enforces HIPAA's minimum necessary rule — users and systems access only the PHI required for their specific function:

  • Role-based access levels — Six distinct access levels ensure that each user type (provider, staff, patient, integration) sees only what they need
  • Per-organization session binding — Every session is scoped to a single organization, preventing cross-tenant data exposure (Session Security)
  • API-level scoping — REST endpoints return only data the authenticated identity is entitled to, based on role and organization context
  • Background job isolation — Organization context carries through asynchronous operations, so the minimum necessary boundary holds even outside direct user requests (How Isolation Is Enforced)

Analytics & PHI

Clinical and operational data flows to a dedicated Snowflake analytics warehouse for population health trends and utilization metrics. Snowflake operates under a Business Associate Agreement, so PHI is protected throughout the analytics pipeline without requiring de-identification prior to ingestion.

PHI in Logs & Monitoring

Atticus Health self-hosts its logging and observability infrastructure, ensuring that PHI never leaves controlled environments:

  • Self-hosted observability — All application logs, traces, and metrics are collected in self-hosted infrastructure — no PHI is sent to third-party log aggregation services
  • Application log retention — Logs are retained for 90 days and automatically rotated (Retention Policies)
  • Audit log separation — Audit logs that record PHI access are retained for 7 years in a dedicated audit database, separate from application logs
  • Error reporting — Error payloads are sanitized before capture to prevent unintentional PHI exposure in diagnostic tooling

Business Associate Agreements

Atticus Health maintains BAA coverage across all relationships that involve PHI:

RelationshipScopeWhen Executed
Infrastructure providersCloud hosting, storage, and managed services that may process or store PHIBefore infrastructure provisioning
CustomersCovered entities that transmit PHI to the Atticus Health platformBefore PHI enters the platform
Integration partnersThird-party systems that exchange data through platform APIsBefore integration activation

Patient Rights

Atticus Health provides platform-level support for HIPAA's individual rights:

RightPlatform Support
AccessPatients view their records through the patient app; clinical data exportable via FHIR
AmendmentAmendment request workflow with provider review and full audit trail
Accounting of DisclosuresPHI access audit logs retained 7 years; per-patient disclosure reports available
RestrictionsRestriction flags enforceable at the record level
Confidential CommunicationsPatient-configurable communication channels (email, SMS) and preferences

Third-Party Data Sharing

All external data exchange is controlled through platform-enforced safeguards:

  • Authenticated API access — All integrations use the Server-to-Server access level with scoped credentials
  • Minimum necessary scoping — Each integration's API access is limited to the data required for its function
  • FHIR for clinical exchange — Clinical data sharing follows the FHIR standard for interoperability
  • BAA required — No integration partner receives PHI until a Business Associate Agreement is in place

Shared Responsibility

PHI protection is a shared obligation between Atticus Health and its customers:

ResponsibilityAtticus Health (Platform)Customer (Covered Entity)Shared
Infrastructure securityEncryption, network isolation, access controls
Application securityAuthentication, authorization, audit logging
Workforce trainingPlatform operations teamCustomer staff HIPAA training
Access managementPlatform-level role enforcementUser provisioning and role assignmentBAA defines boundary
Breach notificationDetection, containment, 24-hour notificationPatient and regulator communicationCoordinated response
Policy and proceduresPlatform security policiesCovered entity policiesBAA defines boundary

The Business Associate Agreement between Atticus Health and each customer defines the precise boundary of responsibility. Atticus Health secures the platform; customers retain their obligations as covered entities under HIPAA.