HIPAA & Compliance

HostSwarm is designed from the ground up for HIPAA alignment. Our architecture minimizes PHI risk through zero data retention and sovereign infrastructure.

Disclaimer: HostSwarm is designed for HIPAA alignment but is not yet formally certified. We provide a BAA upon request.

Security Architecture

🔒
Zero PHI Retention
DICOM files are processed in memory and immediately deleted. No PHI is stored on disk or in logs.
🏠
Sovereign Infrastructure
We own all 296 GPUs. No cloud providers, no third-party access, no data leaving our facility.
🔑
Cryptographic Auth
Ed25519 signatures for every request. No passwords to steal, no tokens to leak.
📋
Audit Trail
Every API call is logged with client ID, timestamp, and operation. ENS identity provides immutable attribution.

Data Handling

What We Process

What We Store

Data TypeStored?Duration
DICOM filesNoDeleted immediately after processing
Patient names/IDsNoNever stored
AI-generated reportsNoReturned to client, not stored
API request logsYes30 days (no PHI)
Billing recordsYes7 years (no PHI)

Data Flow

  1. Client uploads DICOM via TLS 1.3 encrypted connection
  2. DICOM stored in encrypted RAM (never touches disk)
  3. AI inference runs on our GPUs
  4. PDF report generated and returned to client
  5. All DICOM data purged from memory
  6. Only metadata logged: timestamp, client ID, inference time

HIPAA Alignment

Key Principle: The best way to protect PHI is to not store it.

Technical Safeguards

Physical Safeguards

Administrative Safeguards

Business Associate Agreement

We provide a BAA for covered entities. To request a BAA:

  1. Email compliance@hostswarm.io
  2. Include your organization name and contact
  3. We'll send our standard BAA for review

Compliance Roadmap

MilestoneStatus
HIPAA-aligned architectureComplete
BAA templateComplete
SOC 2 Type IIn Progress
SOC 2 Type IIPlanned
HITRUSTPlanned

Questions?

For compliance questions or to request our security documentation: