HIPAA Privacy Practices
HIPAA Privacy Practices
Effective Date:
Our Role and Commitment
Elderwise (operated by Ajentik AI Pte. Ltd.) acts as a Business Associate under HIPAA. We process Protected Health Information (PHI) on behalf of healthcare organizations (Covered Entities) that use our platform. Security and privacy controls are designed to support applicable HIPAA obligations. Current scope and supporting documentation are available to qualified organizations through a security review. We implement safeguards to protect all PHI entrusted to us.
How We Handle Protected Health Information
Care Coordination Support
We process PHI to support care coordination between caregivers and healthcare providers. Our AI-guided questionnaires generate structured summaries that clinicians can review.
As Directed by Covered Entities
We use and disclose PHI only as permitted or required by our Business Associate Agreements and applicable law. We do not independently use PHI for payment or operations.
Platform Operations
We may use de-identified data (per HIPAA Safe Harbor) to improve our platform. PHI is used only as authorized under our Business Associate Agreements.
Your Rights Regarding Your Health Information
- Right to Inspect and Copy: You have the right to access your PHI. Because we act as a Business Associate, please direct access requests to your healthcare provider (the Covered Entity). We will assist them in fulfilling your request.
- Right to Amend: You may request amendments to your PHI through your healthcare provider. We will implement approved amendments promptly.
- Right to an Accounting of Disclosures: You may request an accounting of disclosures we have made of your PHI. Contact your healthcare provider or email us at dpo@ajentik.ai.
Data Security
We implement administrative, physical, and technical safeguards to protect PHI:
- AES-256 encryption at rest and TLS encryption in transit.
- Role-based access controls that limit PHI access to authorized personnel.
- Audit logging of access to and activity involving PHI.
- Security monitoring to detect and respond to potential threats.
- Backup and recovery procedures to support data availability.
- Workforce training on privacy and security responsibilities.