Security
HIPAA-aligned by design — not by marketing claim
Spark is built for clinical operations with encryption, tenant isolation, audit logging, and human oversight. We do not claim third-party certification we have not completed.
BAA required before live PHI · No PHI in marketing lead forms
Architecture & governance
These invariants apply to every phase, feature, experiment, and customer deployment.
Non-negotiable controls
- HIPAA-aligned architecture with vendor review before new external services
- Business Associate Agreements signed before PHI enters external AI or automation
- Strict tenant isolation — one practice’s data never enters another’s context
- No PHI in unapproved tools, logs, or marketing materials
- Complete access and activity audit trail extended with every new surface
- Human approval for clinical decisions, prescriptions, chart notes, and uncertain matches
- Low-confidence automation escalates — it never silently acts
- Patient requests land in real work queues staff actually use
Production operations
- Encryption in transit and at rest on AWS infrastructure
- Staged deploys: dev → staging, main → production
- Per-clinic operational feature flags for voice, scheduling, and EHR writes
- Documented rollback runbook with reconciliation checks after incidents
- Ops alerts to on-call channels for production failures
Transparency: Spark is pursuing HIPAA readiness and security hardening as the platform evolves. We do not represent SOC 2 Type I or other certifications as complete unless and until they are verified and published.