Controls at a glance

AreaPosture
HIPAABAA available for all covered entities; see /baa
Encryption in transitTLS 1.2 or higher on all endpoints
Encryption at restAES-256 for stored PHI and backups
Data residencyUnited States only
Model trainingPHI is not used to train any foundation model
Access controlRole-based, least privilege, immutable audit log
AuthenticationSSO (SAML/OIDC) available; MFA required for staff
RetentionConfigurable per practice; default minimum for regulatory compliance
Breach notificationPer BAA, within 60 days of discovery (most cases within days)
Third-party processorsEach covered by a downstream BAA where PHI is involved
SOC 2Type II audit in progress; interim attestation on request

What MAIA does not do

Frequently asked questions

Is MAIA HIPAA compliant?

MAIA is built HIPAA-aware and enters into a Business Associate Agreement (BAA) with every covered entity before any PHI is processed. The BAA template is available for review.

Where is patient data stored?

All PHI is processed on US-based infrastructure. No data is transferred outside the United States. Storage is encrypted at rest using industry-standard algorithms; connections are encrypted in transit with TLS 1.2 or higher.

Do you use patient data to train AI models?

No. Patient PHI is used solely to deliver the services the practice has requested. It is not used to train foundation models, not shared with third-party model providers for training, and not sold or licensed.

Are you SOC 2 certified?

SOC 2 Type II audit is in progress. Interim attestation documents and our security-control inventory are available under NDA on request.

Who at MAIA can access my practice's data?

Access is role-restricted and logged. Support and engineering staff reach customer data only when responding to an authorized request. All access events are recorded in an immutable audit log available to the practice on request.

Need the full security package?

Contact us for a copy of the BAA, the SOC 2 interim attestation, and the control inventory spreadsheet.

Request security documents