Spark
Security

HIPAA-aligned by design — not by marketing claim

Spark is built for clinical operations with encryption, tenant isolation, audit logging, and human oversight. We do not claim third-party certification we have not completed.

BAA required before live PHI · No PHI in marketing lead forms

Architecture & governance

These invariants apply to every phase, feature, experiment, and customer deployment.

Non-negotiable controls

  • HIPAA-aligned architecture with vendor review before new external services
  • Business Associate Agreements signed before PHI enters external AI or automation
  • Strict tenant isolation — one practice’s data never enters another’s context
  • No PHI in unapproved tools, logs, or marketing materials
  • Complete access and activity audit trail extended with every new surface
  • Human approval for clinical decisions, prescriptions, chart notes, and uncertain matches
  • Low-confidence automation escalates — it never silently acts
  • Patient requests land in real work queues staff actually use

Production operations

  • Encryption in transit and at rest on AWS infrastructure
  • Staged deploys: dev → staging, main → production
  • Per-clinic operational feature flags for voice, scheduling, and EHR writes
  • Documented rollback runbook with reconciliation checks after incidents
  • Ops alerts to on-call channels for production failures
Transparency: Spark is pursuing HIPAA readiness and security hardening as the platform evolves. We do not represent SOC 2 Type I or other certifications as complete unless and until they are verified and published.