Legal

HIPAA & PHI Notice

Last updated: July 9, 2026

Do not enter Protected Health Information (PHI) into AVD Clinical. AVD Clinical is not a HIPAA Covered Entity. No Business Associate Agreement (BAA) is currently available. Covered entities and business associates must not use this Service to process PHI without a signed Enterprise Agreement that includes a BAA.

1. Our HIPAA Status at a Glance

Not applicable

HIPAA Covered Entity

AVD Clinical is not a healthcare provider, health plan, or healthcare clearinghouse. We are not a Covered Entity under 45 CFR § 160.103.

Not currently available

Business Associate Agreement (BAA)

No BAA is available at this time. A BAA framework is planned for the future regulated Enterprise platform. Contact us if your organization requires one.

Prohibited

PHI Processing

Uploading, entering, or transmitting PHI into any part of the current Service is prohibited by our Terms of Service.

Live now

Health-Sensitive Data Protection

Medicine reminder data is encrypted at rest (AES-256) and in transit (TLS), access-controlled by Row-Level Security, and never shared with third parties.

2. What Is PHI?

Protected Health Information (PHI) is individually identifiable health information held or transmitted by a Covered Entity or Business Associate. PHI includes any information that relates to a person's health condition, healthcare, or payment for healthcare AND identifies (or could identify) the individual.

PHI identifiers under HIPAA include (but are not limited to):

3. What AVD Clinical Collects vs. What It Does Not

What we collect

What we do not collect and prohibit

4. Medicine Reminder Tool — Important Clarification

The Medicine Reminder tool allows you to enter your own personal medication information (medicine names, doses, prescribing doctor, pharmacy, refill dates). This is for your personal use only.

This data is not PHI under HIPAA because:

However, we treat this data as health-sensitive and apply strong security controls regardless. See our Security page and Privacy Policy for details.

Do not enter another person's health information into the Medicine Reminder tool. The tool is for your own medications only.

5. HIPAA-Aligned SOPs and Templates

Several AVD Clinical templates reference HIPAA compliance (PHI disclosure logs, breach assessment forms, consent withdrawal forms, etc.). These documents are starting frameworks to help your organization build HIPAA-compliant procedures. They are not pre-validated HIPAA compliance tools. Your organization's compliance team, legal counsel, and Privacy Officer must review and adapt these documents before operational use.

Purchasing and using these templates does not make your organization HIPAA-compliant. Compliance requires implementation of administrative, physical, and technical safeguards across your entire organization, executed BAAs with all business associates, staff training, risk assessments, and ongoing audit programs.

6. For Covered Entities — What To Do

If your organization is a HIPAA Covered Entity or Business Associate and you wish to use AVD Clinical tools in workflows that may involve PHI:

7. Security Safeguards Applied to Health-Sensitive Data

Although not required by HIPAA, we apply the following controls to all health-sensitive data (medicine reminder data):

See our full Security page for technical details.

8. Questions

For questions about HIPAA compliance, PHI handling, or enterprise BAA inquiries:
AVD Clinical
Email: info@avdclinical.com
Phone: +1 929-502-4973