Overview
FaceofMind is developing support for HIPAA-covered deployments and will offer a Business Associate Agreement (BAA) to eligible Covered Entities and Business Associates. This page details our compliance framework and technical preparedness.
📋1. What Our BAA Will Cover
- Permitted Uses: FaceofMind will process PHI only as directed by the Covered Entity. Uses are strictly restricted to clinical dashboard summaries, mood metrics, voice audits, and crisis warning detections.
- No Secondary Data Exploitation: Secondary uses of PHI (including targeted marketing, insurer disclosures, or third-party ad sales) are strictly prohibited.
- Workforce Guardrails: Regular security training, workforce access limitations, and documented policy enforcement procedures.
2. Security Safeguards (45 CFR §164.308–318)
FaceofMind implements technical, administrative, and organizational safeguards designed to protect electronic protected health information (ePHI). Additional technical documentation is available upon request during enterprise security review.
3. HIPAA Breach Notification & Response (45 CFR §164.400–414)
Our breach response protocols align with the HIPAA Breach Notification Rule. FaceofMind will provide notifications of any confirmed security incidents affecting ePHI within the timelines required by applicable law and any executed Business Associate Agreements.
4. HIPAA Sub-Contractors & Sub-Processors
We manage HIPAA commitments with subcontractors who touch Protected Health Information (PHI):
FaceofMind maintains a Business Associate Agreement with Google Cloud for applicable HIPAA services used in hosting and storage.
Any auxiliary cloud processors touching ePHI are operated within HIPAA-compliant configurations. Specific service BAA statuses are available on request during enterprise review.
5. Data Retention & Deletion Schedule
| Data Type | Retention Policy |
|---|---|
| ePHI & Mood logs | Retention periods vary based on applicable law, customer requirements, and contractual obligations. |
| Voice Logs & Metrics | Retention periods vary based on applicable law, customer requirements, and contractual obligations. |
| Consultation records | Retention periods vary based on applicable law, customer requirements, and contractual obligations. |
| Audit logs | Security audit trail tracking maintained per regulatory requirements. |
Contract Termination: Upon termination of a customer agreement, ePHI is returned or securely destroyed in accordance with the terms of the executed BAA and applicable legal requirements.
6. Customer Audit Rights
Subject to confidentiality, security, and operational requirements, FaceofMind may provide relevant documentation or evidence supporting compliance with agreed security obligations.
🛡️7. HIPAA Readiness Status
FaceofMind is actively developing its HIPAA program. Availability of BAAs and supporting compliance documentation will be announced when operationally ready.
• HIPAA Readiness: Program and technical safeguard alignments are in progress.
• BAA Availability: Business Associate Agreements will be made available for selected enterprise deployments once operational requirements are met.
• Inquiries: Contact our legal team for availability, pilot requirements, and readiness updates.
8. How to Request a BAA
Organizations requiring a Business Associate Agreement or wishing to participate in early enterprise pilot programs can initiate a request:
1. Contact Legal: Send an inquiry to legal@faceofmind.com.
2. Information Needed: Please include your organization name, your role (Covered Entity or Business Associate), and your proposed timeline or deployment requirements.