HIPAA & PHI

HIPAA & Protected Health Information

Guidance for covered entities and business associates evaluating PowerChart90. This page is informational and is not legal advice.

Effective date: August 17, 2026 · Last updated: August 17, 2026

Default rule for public evaluation: use synthetic or fully de-identified charts. If PHI may be disclosed, execute a BAA first and obtain counsel approval.

1. What leaves your device

After browser-side extraction (when used), PowerChart90 transmits notes and related fields to our remote analysis function. Treat every scan as a disclosure to PDPM Audit Group and, when LLM mode is enabled, potentially to model subprocessors listed on Privacy and Security.

2. De-identification

Before upload, remove or replace direct identifiers where feasible (names, SSNs, full street addresses, account numbers, precise contacts, and similar). Facility counsel should decide whether Safe Harbor or Expert Determination applies.

3. Minimum necessary

Submit only the documentation needed for the audit-readiness review. Prefer scoped packets over entire EHRs when possible.

4. BAA

Request and countersign a BAA via /baa/ before PHI disclosure. Product checkboxes acknowledge obligations; they do not replace counsel-required long-form agreements.

5. Product limitations under HIPAA programs

Automated findings are not a certification of HIPAA Security Rule compliance for your facility, nor proof that a particular claim or MDS item will withstand audit. Human review remains required.