Security & privacy
Private by default, auditable by design
Clarity handles referral packets and patient records with HIPAA-aligned controls: a private VPC, hard tenant and patient isolation, encryption everywhere, and an audit trail behind every decision.
How data is handled
The controls your reviewers will ask about
Clarity was built for regulated healthcare data from the start. Six controls sit underneath every screen of the product.
HIPAA-aligned handling
Clarity operates as a business associate under a BAA, with HIPAA-aligned controls end to end: how data is stored, who can touch it, and how every touch is recorded.
Private by default
Services run inside a private VPC with no public endpoints, and every service-to-service call is IAM-signed. Nothing talks to anything without proving who it is.
Hard tenant and patient isolation
Every query is scoped to one tenant and one patient. Isolation is verified in evaluation, not assumed from the architecture diagram.
Role-based access
People see what their role needs and nothing else. Admissions, billing, and administrators each get their own view of the record.
Audit logging
Every view, recommendation, decision, and override is logged with who and when. The trail is the point.
Encryption, clean logs
Data is encrypted in transit and at rest, and PHI is scrubbed from application logs. Patient data doesn’t leak into the plumbing.
Demo environments and screenshots use synthetic patients only: Robert Davis · 73 · MRN 8472301 is not a real person.
Responsible AI
The AI shows its work and your team makes the call
Nothing Clarity says stands on its own authority. Every answer is tied to the source chart: the exact quote, on the exact page, one click from the claim. And when the packet doesn’t hold the answer, Clarity flags insufficient evidence instead of guessing.
- Clarity recommends; your team makes the accept or decline
- Ambiguous findings come back as needs review, not auto-decided
- Overrides require a note and are audit-logged
Deal-breaker · Pain management
“Pain well controlled on Tylenol 650mg q6h… 3/10 at rest”
Clarity Beacon · launching soon
Guardrails designed in, not bolted on
Clarity Beacon, care-transition alerts launching soon, is being built with its privacy limits as design principles, not settings.
Monitoring will be bounded to a hard 31-day post-discharge window, then unsubscribe automatically. The window brackets Medicare’s 30-day return rule exactly.
Treatment and care coordination only. No population analytics, no surveillance, no model training.
No monitoring of anyone you declined, and no patient details in the alert ping itself.
Why 31 days: a patient who returns to skilled care within 30 days of discharge needs no new qualifying hospital stay, so monitoring ends the day that logic does.
Bring your security team
We’ll walk your security or compliance reviewers through the architecture, the isolation evaluation, and the audit trail, and we’ll route your security questionnaire.