Compliance · Updated July 2026

HIPAA compliance for law firms using AI medical chronology software

Law firms that upload medical records to any software vendor are sharing protected health information (PHI) with a Business Associate — and HIPAA requires a signed BAA before that first file is sent. Here is how Chronos meets those obligations, and what to look for when evaluating any AI tool for medical record review.

Signed BAA — every accountAES-256 at restTLS 1.3 in transitSOC 2 readiness programUS-only data residencyPHI never used for training
// The legal obligation

Why law firms need a BAA with their AI vendor

Under 45 CFR §164.308(b), a covered entity — or any Business Associate that further subcontracts PHI — must enter a written Business Associate Agreement with every vendor that creates, receives, maintains, or transmits PHI on its behalf.

A law firm that uploads medical records to an AI tool is sharing PHI with that tool's operator. Using a vendor without a BAA violates HIPAA regardless of whether the vendor uses the word "secure" in its marketing — the regulatory requirement is the agreement itself, not just the technical controls.

The HHS Office for Civil Rights (OCR) has issued enforcement actions specifically for covered entities and BAs that failed to execute BAAs with subcontractors. Fines range from $100 to $50,000 per violation, with annual caps up to $1.9M per violation category.

What a BAA must cover (45 CFR §164.504(e))

Permitted uses and disclosures of PHI
Prohibition on uses not permitted by the covered entity
Requirement to implement appropriate safeguards
Requirement to report breaches and security incidents
Requirement to make PHI available for patient access requests
Requirement to return or destroy PHI at contract termination
Authorization to subcontract only to compliant subprocessors

Source: HHS.gov — Business Associate Contracts

// 45 CFR §164.312

Technical safeguards — how Chronos addresses each

The HIPAA Security Rule's Technical Safeguards standard (45 CFR §164.312) specifies the controls required for electronic PHI. Here's how Chronos maps to each implementation specification.

Chronos vs. HIPAA Technical Safeguards (45 CFR §164.312) — July 2026
RegulationSafeguardHow Chronos addresses it
§164.312(a)(1)Access controlUnique user IDs, automatic session logoff, and role-based permissions. Each team member can reach only the cases and actions they need — no shared logins.
§164.312(a)(2)(iv)Encryption & decryptionPHI is encrypted at rest with AES-256 and in transit with TLS 1.3. Keys are held in a dedicated key management service (KMS) and rotated on a schedule.
§164.312(b)Audit controlsEvery view, edit, export, and login is recorded in a tamper-evident audit log. The log is exportable at any time for an internal or external compliance review.
§164.312(c)(1)Integrity controlsControls verify that PHI has not been improperly altered or destroyed. Checksums are maintained on stored records.
§164.312(d)Person or entity authenticationMulti-factor authentication (MFA) is enforced for all accounts. SSO via SAML 2.0 and SCIM provisioning are available for enterprise clients.
§164.312(e)(1)Transmission securityTLS 1.3 protects all data in transit. No PHI travels over unencrypted channels.

Administrative and Physical Safeguards (§164.308, §164.310) are covered in our Security overview and in our security documentation package, available under NDA.

// Business Associate Agreement

Every account includes a signed BAA — no exceptions.

We don't require an enterprise plan, a minimum seat count, or a separate contract process for a BAA. Solo practitioners and large firms get the same agreement.

The BAA is presented during onboarding before any files are uploaded. If you need to share the agreement with your IT, compliance, or procurement team before signing up, contact us and we'll provide the template immediately.

Covers all PHI uploaded to Chronos
Describes permitted uses (chronology creation only)
Commits to breach notification within 72 hours
Prohibits use of PHI for AI model training
Requires destruction of PHI on contract termination
Lists all subprocessors on request

Request our security documents

We share our BAA template, subprocessor list, and standard security questionnaire response under a mutual NDA.

BAA templateAvailable before sign-up
SOC 2 readiness programReport available when our audit completes
Security questionnaire responseStandard + custom
Subprocessor listCurrent, on request
Contact sales for security docs
// Data retention & deletion

How long we keep PHI — and how to delete it

Active records

Medical records and chronologies are retained for as long as your account is active. Active cases have no automatic expiry — you control when to delete them. Cases you delete are purged on a configurable retention window (30 days by default, minimum 7).

Deleted cases

When you delete a case, the records and output are permanently removed from active storage within 30 days. Deleted data ages out of all backups within 12 months (daily backups are retained for 30 days; monthly backups are retained for 12 months). Deletion is logged in the audit trail.

Account closure

When you close your account, all PHI is deleted on the same schedule. You can request a full data export before closing. We do not retain PHI after contract termination.

Audit logs

Activity logs (who viewed, exported, or edited records) are retained for 6 years in compliance with HIPAA's documentation requirements under 45 CFR §164.316(b).

Backups

Daily backups are retained for 30 days; monthly backups are retained for 12 months. All backup data is encrypted with AES-256 and subject to the same access controls as primary storage.

AI processing

PHI is passed to our AI pipeline for chronology generation only. It is not stored in the AI system after processing is complete, and it is never used for model training.

// Due diligence

HIPAA vendor checklist for AI medical record tools

Use this checklist when evaluating any AI tool that will receive PHI from your firm — including Chronos. Every item should be documented before the first file is shared.

HIPAA vendor due diligence checklist for law firms — AI medical record tools
Due diligence itemChronos
Will the vendor sign a Business Associate Agreement (BAA)?Yes — included with every account, no extra cost
AES-256 encryption at rest?Yes
TLS 1.3 in transit?Yes
Data stored in the United States only?Yes — US-only data residency
PHI used to train AI models?No — never, contractually
Security documentation available (BAA, questionnaire)?Yes — documentation package available under NDA
Per-user audit log exportable?Yes — full tamper-evident log
Multi-factor authentication enforced?Yes — required for all accounts
Right-to-delete (account + records)?Yes — permanent deletion, logged
Subprocessor list available?Yes — published at /subprocessors
// FAQ

HIPAA compliance questions

HIPAA-covered from your first upload.

Every account includes a signed BAA — no enterprise plan required. Start your first case free, or contact sales for our full security documentation.