1. Introduction
At CarePilot, protecting patient privacy and earning the trust of clinicians are our highest priorities. This overview explains, in plain language, how we handle Protected Health Information (PHI), how long we retain it, and the safeguards we apply throughout its lifecycle.
2. Key Definitions
Term | Definition |
"Retention Period" | The time PHI Data remains in our encrypted primary systems. • Enterprise / Integrated Accounts: 180 days by default (customizable up to 365 days by agreement). • Standalone Accounts: 14 days. |
"Disaster Recovery Period" | Up to 30 days immediately following the end of the Retention Period during which encrypted backup copies may persist solely for disaster‑recovery purposes. |
"PHI Data" | Any data subject to HIPAA that CarePilot creates or processes, including: clinical notes, visit transcripts (text or audio), appointment and demographic details, diagnoses, problems, procedure and billing codes, and related metadata. |
3. Data Lifecycle
Active Storage (Retention Period) — PHI Data resides in US based encrypted primary storage for the duration of the applicable Retention Period. After expiry, data is securely deleted on a rolling basis.
Backups (Disaster Recovery Period) — US based encrypted backups that may contain PHI Data are retained for up to 30 days after deletion from primary storage. These backups exist only to restore service continuity and are automatically and permanently deleted once the Disaster Recovery Period ends.
4. Use of PHI Data
PHI Data is never used to train or improve CarePilot’s AI models.
However, in accordance with 45 C.F.R. § 164.514(b)(2) (the HIPAA Safe Harbor de-identification standard) and as expressly permitted under our Business Associate Agreements (BAAs), CarePilot may create and use properly de-identified data to enhance and improve its services.
De-identified data is not associated with your organization or any individual and is not subject to CarePilot’s PHI retention or deletion policies.
All model training or improvement activities are conducted in full alignment with HIPAA privacy and security safeguards and within the scope permitted under each customer’s BAA.
5. Third-Party Model Providers
CarePilot operates exclusively on HIPAA‑compliant Amazon Web Services (AWS) infrastructure located in the United States.
All text-based AI inference requests are processed through Microsoft Azure OpenAI or OpenAI API under HIPAA‑eligible configurations. No request payloads are stored persistently by OpenAI.
We hope this gives you peace of mind about how CarePilot uses your data. By keeping everything secure and personalized just for you, we aim to make your documentation process easier, faster, and more efficient.
If you have any further questions, feel free to reach out to our support team.
