Tabula Medica

Trust Center

Tabula Medica is a FHIR-native, security-first health record platform. Protected health information (PHI) is processed only on HIPAA-eligible infrastructure under a Business Associate Agreement (BAA). This page documents our encryption posture, compliance status, and an honest model card for every AI feature.

Encryption Attestation

All electronic PHI (ePHI) is encrypted at rest and in transit by default.

PHI at restAES-256-GCM (GCP Healthcare API / CMEK-eligible)
Data in transitTLS 1.2+ (HSTS enforced, platform-managed certificates)
Key managementCloud KMS with rotation; field-level encryption for sensitive data
BackupsEncrypted at rest with the same AES-256 standard

Compliance Posture

Where each framework stands today. We build to the proposed 2026 HIPAA Security Rule now — mandatory encryption, phishing-resistant MFA, network segmentation, and annual penetration testing — so we are compliant before it is final.

HIPAA

Active

PHI handled under BAA on HIPAA-eligible GCP infrastructure

SOC 2 Type II

In progress

Controls mapped; audit window scheduled Q2 2026

HITRUST

In progress

CSF control mapping aligned to SOC 2 evidence

ISO 27001

Designed / ready

ISMS controls designed; certification on roadmap

FHIR R4 / US Core

Active

USCDI v3 endpoints for standards-based exchange

SMART on FHIR

Active

OAuth2 + PKCE app-launch for EHR connectivity

2026 HIPAA Security Rule (proposed)

Designed / ready

Built to the proposed rule: mandatory encryption, MFA, segmentation

AI Safety — Assist, Never Advise

Our AI assists; it does not give medical advice. Clinical Decision Support is disabled. AI features explain, summarize, and draft — a licensed clinician reviews anything that reaches a patient. Guardrails detect and refuse medical-advice requests, and PHI is redacted from all logs.

AI-drafted patient communications carry an AI-generated disclosure where state law requires it (e.g. California AB 3030); a clinician review suppresses the disclaimer per that law, so patients never receive unreviewed robo-messages.

AI Model Cards

One card per patient-facing AI feature. Every model runs on Google Vertex AI (Gemini) under our GCP BAA — no PHI is ever sent to a non-BAA AI provider.

AI Health Summary

Model: Google Vertex AI (Gemini) under GCP BAA

Data sent: Patient's own records (problems, meds, labs) — never shared across patients

Human in the loop: Educational summary only; clinician reviews before any patient-facing message is sent

Known failure modes: May omit nuance from unstructured notes; never used for diagnosis or treatment decisions

Medical Term Explanations

Model: Google Vertex AI (Gemini) under GCP BAA

Data sent: The term plus minimal surrounding context the patient is viewing

Human in the loop: Definitions are general education, not advice; refusal guardrails block advice requests

Known failure modes: Plain-language simplification can lose specificity; links back to source records

Document Extraction Pipeline

Model: Multi-model extraction via Vertex AI (Gemini) under GCP BAA

Data sent: Uploaded medical documents (BAA-covered storage)

Human in the loop: Human-in-the-loop validation queue before extracted data is committed

Known failure modes: OCR/extraction errors on poor scans; low-confidence fields flagged for review

Symptom Checker (Triage)

Model: Google Vertex AI (Gemini) under GCP BAA

Data sent: Self-reported symptoms entered by the patient

Human in the loop: Urgency guidance only, not a diagnosis; emergencies routed to call 911

Known failure modes: Cannot examine the patient; always defers to a licensed clinician for decisions

Voice / Ambient SOAP Scribe

Model: Speech-to-text + Vertex AI (Gemini) structuring, under GCP BAA

Data sent: Encounter audio transcript (clinician + patient)

Human in the loop: Clinician edits and signs every note; nothing is filed automatically

Known failure modes: Transcription errors on overlapping speech / drug names; clinician correction required

Patient Message Drafting

Model: Google Vertex AI (Gemini) under GCP BAA

Data sent: The specific result or context the message is about

Human in the loop: Clinician approves every draft; AI-disclosure applied per state law unless clinician-reviewed

Known failure modes: Tone/omission errors; clinician sign-off gate prevents unreviewed sends

Reporting & Contact

Security inquiries, BAA requests, or vulnerability reports: security@tabulamedica.com. See our coordinated disclosure policy at /.well-known/security.txt. Detailed architecture lives on the Security & Compliance page.

Take Control of Your Health Records

Unified, summarized, deduplicated, and shareable — all in one place.

Get Started