Trust Center
Tabula Medica is a FHIR-native, security-first health record platform. Protected health information (PHI) is processed only on HIPAA-eligible infrastructure under a Business Associate Agreement (BAA). This page documents our encryption posture, compliance status, and an honest model card for every AI feature.
Encryption Attestation
All electronic PHI (ePHI) is encrypted at rest and in transit by default.
| PHI at rest | AES-256-GCM (GCP Healthcare API / CMEK-eligible) |
|---|---|
| Data in transit | TLS 1.2+ (HSTS enforced, platform-managed certificates) |
| Key management | Cloud KMS with rotation; field-level encryption for sensitive data |
| Backups | Encrypted at rest with the same AES-256 standard |
Compliance Posture
Where each framework stands today. We build to the proposed 2026 HIPAA Security Rule now — mandatory encryption, phishing-resistant MFA, network segmentation, and annual penetration testing — so we are compliant before it is final.
HIPAA
Active
PHI handled under BAA on HIPAA-eligible GCP infrastructure
SOC 2 Type II
In progress
Controls mapped; audit window scheduled Q2 2026
HITRUST
In progress
CSF control mapping aligned to SOC 2 evidence
ISO 27001
Designed / ready
ISMS controls designed; certification on roadmap
FHIR R4 / US Core
Active
USCDI v3 endpoints for standards-based exchange
SMART on FHIR
Active
OAuth2 + PKCE app-launch for EHR connectivity
2026 HIPAA Security Rule (proposed)
Designed / ready
Built to the proposed rule: mandatory encryption, MFA, segmentation
AI Safety — Assist, Never Advise
Our AI assists; it does not give medical advice. Clinical Decision Support is disabled. AI features explain, summarize, and draft — a licensed clinician reviews anything that reaches a patient. Guardrails detect and refuse medical-advice requests, and PHI is redacted from all logs.
AI-drafted patient communications carry an AI-generated disclosure where state law requires it (e.g. California AB 3030); a clinician review suppresses the disclaimer per that law, so patients never receive unreviewed robo-messages.
AI Model Cards
One card per patient-facing AI feature. Every model runs on Google Vertex AI (Gemini) under our GCP BAA — no PHI is ever sent to a non-BAA AI provider.
AI Health Summary
Model: Google Vertex AI (Gemini) under GCP BAA
Data sent: Patient's own records (problems, meds, labs) — never shared across patients
Human in the loop: Educational summary only; clinician reviews before any patient-facing message is sent
Known failure modes: May omit nuance from unstructured notes; never used for diagnosis or treatment decisions
Medical Term Explanations
Model: Google Vertex AI (Gemini) under GCP BAA
Data sent: The term plus minimal surrounding context the patient is viewing
Human in the loop: Definitions are general education, not advice; refusal guardrails block advice requests
Known failure modes: Plain-language simplification can lose specificity; links back to source records
Document Extraction Pipeline
Model: Multi-model extraction via Vertex AI (Gemini) under GCP BAA
Data sent: Uploaded medical documents (BAA-covered storage)
Human in the loop: Human-in-the-loop validation queue before extracted data is committed
Known failure modes: OCR/extraction errors on poor scans; low-confidence fields flagged for review
Symptom Checker (Triage)
Model: Google Vertex AI (Gemini) under GCP BAA
Data sent: Self-reported symptoms entered by the patient
Human in the loop: Urgency guidance only, not a diagnosis; emergencies routed to call 911
Known failure modes: Cannot examine the patient; always defers to a licensed clinician for decisions
Voice / Ambient SOAP Scribe
Model: Speech-to-text + Vertex AI (Gemini) structuring, under GCP BAA
Data sent: Encounter audio transcript (clinician + patient)
Human in the loop: Clinician edits and signs every note; nothing is filed automatically
Known failure modes: Transcription errors on overlapping speech / drug names; clinician correction required
Patient Message Drafting
Model: Google Vertex AI (Gemini) under GCP BAA
Data sent: The specific result or context the message is about
Human in the loop: Clinician approves every draft; AI-disclosure applied per state law unless clinician-reviewed
Known failure modes: Tone/omission errors; clinician sign-off gate prevents unreviewed sends
Reporting & Contact
Security inquiries, BAA requests, or vulnerability reports: security@tabulamedica.com. See our coordinated disclosure policy at /.well-known/security.txt. Detailed architecture lives on the Security & Compliance page.
Take Control of Your Health Records
Unified, summarized, deduplicated, and shareable — all in one place.
Get Started