Law firms that upload medical records to any software vendor are sharing protected health information (PHI) with a Business Associate — and HIPAA requires a signed BAA before that first file is sent. Here is how Chronos meets those obligations, and what to look for when evaluating any AI tool for medical record review.
Under 45 CFR §164.308(b), a covered entity — or any Business Associate that further subcontracts PHI — must enter a written Business Associate Agreement with every vendor that creates, receives, maintains, or transmits PHI on its behalf.
A law firm that uploads medical records to an AI tool is sharing PHI with that tool's operator. Using a vendor without a BAA violates HIPAA regardless of whether the vendor uses the word "secure" in its marketing — the regulatory requirement is the agreement itself, not just the technical controls.
The HHS Office for Civil Rights (OCR) has issued enforcement actions specifically for covered entities and BAs that failed to execute BAAs with subcontractors. Fines range from $100 to $50,000 per violation, with annual caps up to $1.9M per violation category.
The HIPAA Security Rule's Technical Safeguards standard (45 CFR §164.312) specifies the controls required for electronic PHI. Here's how Chronos maps to each implementation specification.
| Regulation | Safeguard | How Chronos addresses it |
|---|---|---|
| §164.312(a)(1) | Access control | Unique user IDs, automatic session logoff, and role-based permissions. Each team member can reach only the cases and actions they need — no shared logins. |
| §164.312(a)(2)(iv) | Encryption & decryption | PHI is encrypted at rest with AES-256 and in transit with TLS 1.3. Keys are held in a dedicated key management service (KMS) and rotated on a schedule. |
| §164.312(b) | Audit controls | Every view, edit, export, and login is recorded in a tamper-evident audit log. The log is exportable at any time for an internal or external compliance review. |
| §164.312(c)(1) | Integrity controls | Controls verify that PHI has not been improperly altered or destroyed. Checksums are maintained on stored records. |
| §164.312(d) | Person or entity authentication | Multi-factor authentication (MFA) is enforced for all accounts. SSO via SAML 2.0 and SCIM provisioning are available for enterprise clients. |
| §164.312(e)(1) | Transmission security | TLS 1.3 protects all data in transit. No PHI travels over unencrypted channels. |
Administrative and Physical Safeguards (§164.308, §164.310) are covered in our Security overview and in our security documentation package, available under NDA.
We don't require an enterprise plan, a minimum seat count, or a separate contract process for a BAA. Solo practitioners and large firms get the same agreement.
The BAA is presented during onboarding before any files are uploaded. If you need to share the agreement with your IT, compliance, or procurement team before signing up, contact us and we'll provide the template immediately.
We share our BAA template, subprocessor list, and standard security questionnaire response under a mutual NDA.
Medical records and chronologies are retained for as long as your account is active. Active cases have no automatic expiry — you control when to delete them. Cases you delete are purged on a configurable retention window (30 days by default, minimum 7).
When you delete a case, the records and output are permanently removed from active storage within 30 days. Deleted data ages out of all backups within 12 months (daily backups are retained for 30 days; monthly backups are retained for 12 months). Deletion is logged in the audit trail.
When you close your account, all PHI is deleted on the same schedule. You can request a full data export before closing. We do not retain PHI after contract termination.
Activity logs (who viewed, exported, or edited records) are retained for 6 years in compliance with HIPAA's documentation requirements under 45 CFR §164.316(b).
Daily backups are retained for 30 days; monthly backups are retained for 12 months. All backup data is encrypted with AES-256 and subject to the same access controls as primary storage.
PHI is passed to our AI pipeline for chronology generation only. It is not stored in the AI system after processing is complete, and it is never used for model training.
Use this checklist when evaluating any AI tool that will receive PHI from your firm — including Chronos. Every item should be documented before the first file is shared.
| Due diligence item | Chronos |
|---|---|
| Will the vendor sign a Business Associate Agreement (BAA)? | Yes — included with every account, no extra cost |
| AES-256 encryption at rest? | Yes |
| TLS 1.3 in transit? | Yes |
| Data stored in the United States only? | Yes — US-only data residency |
| PHI used to train AI models? | No — never, contractually |
| Security documentation available (BAA, questionnaire)? | Yes — documentation package available under NDA |
| Per-user audit log exportable? | Yes — full tamper-evident log |
| Multi-factor authentication enforced? | Yes — required for all accounts |
| Right-to-delete (account + records)? | Yes — permanent deletion, logged |
| Subprocessor list available? | Yes — published at /subprocessors |
Official guidance on when a Business Associate Agreement is required and what it must contain.
HHS.govThe full text and implementation guidance for 45 CFR Part 164 Technical and Administrative Safeguards.
HHS.govDocumented enforcement cases and penalty amounts for HIPAA violations, including BAA failures.
HHS.govRequirements for notifying affected individuals, HHS, and media following a PHI breach (45 CFR §164.400).
HHS.govEvery account includes a signed BAA — no enterprise plan required. Start your first case free, or contact sales for our full security documentation.