HIPAA & PHI
HIPAA & Protected Health Information
Guidance for covered entities and business associates evaluating PowerChart90. This page is informational and is not legal advice.
Effective date: August 17, 2026 · Last updated: August 17, 2026
1. What leaves your device
After browser-side extraction (when used), PowerChart90 transmits notes and related fields to our remote analysis function. Treat every scan as a disclosure to PDPM Audit Group and, when LLM mode is enabled, potentially to model subprocessors listed on Privacy and Security.
2. De-identification
Before upload, remove or replace direct identifiers where feasible (names, SSNs, full street addresses, account numbers, precise contacts, and similar). Facility counsel should decide whether Safe Harbor or Expert Determination applies.
3. Minimum necessary
Submit only the documentation needed for the audit-readiness review. Prefer scoped packets over entire EHRs when possible.
4. BAA
Request and countersign a BAA via /baa/ before PHI disclosure. Product checkboxes acknowledge obligations; they do not replace counsel-required long-form agreements.
5. Product limitations under HIPAA programs
Automated findings are not a certification of HIPAA Security Rule compliance for your facility, nor proof that a particular claim or MDS item will withstand audit. Human review remains required.