Do not enter Protected Health Information (PHI) into AVD Clinical. AVD Clinical is not a HIPAA Covered Entity. No Business Associate Agreement (BAA) is currently available. Covered entities and business associates must not use this Service to process PHI without a signed Enterprise Agreement that includes a BAA.
1. Our HIPAA Status at a Glance
HIPAA Covered Entity
AVD Clinical is not a healthcare provider, health plan, or healthcare clearinghouse. We are not a Covered Entity under 45 CFR § 160.103.
Business Associate Agreement (BAA)
No BAA is available at this time. A BAA framework is planned for the future regulated Enterprise platform. Contact us if your organization requires one.
PHI Processing
Uploading, entering, or transmitting PHI into any part of the current Service is prohibited by our Terms of Service.
Health-Sensitive Data Protection
Medicine reminder data is encrypted at rest (AES-256) and in transit (TLS), access-controlled by Row-Level Security, and never shared with third parties.
2. What Is PHI?
Protected Health Information (PHI) is individually identifiable health information held or transmitted by a Covered Entity or Business Associate. PHI includes any information that relates to a person's health condition, healthcare, or payment for healthcare AND identifies (or could identify) the individual.
PHI identifiers under HIPAA include (but are not limited to):
- Patient names, addresses, dates of birth, dates of service
- Medical record numbers, account numbers, certificate/license numbers
- Phone numbers, fax numbers, email addresses (of patients)
- Social Security numbers, device identifiers
- Biometric identifiers (fingerprints, retinal scans)
- Full-face photographs or comparable images
- Any other unique identifying number or code
3. What AVD Clinical Collects vs. What It Does Not
What we collect
- Account data: Your name, email, phone, and professional role — this is your data, not patient data.
- Medicine reminder data: Medication information you enter about your own prescriptions. This is personal health information you choose to share, not PHI as defined by HIPAA (which requires a covered entity relationship).
- Calculator data: Study budget parameters you enter (countries, site counts, cost estimates). This is operational/financial data, not patient data.
- Purchase records: Transaction metadata from Stripe. No card details are stored by AVD Clinical.
What we do not collect and prohibit
- Patient names, identifiers, or demographic information from clinical trials
- Medical records, lab results, or clinical outcomes data
- Electronic protected health information (ePHI) of any kind
- Research subject data or trial participant data
4. Medicine Reminder Tool — Important Clarification
The Medicine Reminder tool allows you to enter your own personal medication information (medicine names, doses, prescribing doctor, pharmacy, refill dates). This is for your personal use only.
This data is not PHI under HIPAA because:
- HIPAA only applies to Covered Entities (health plans, providers, clearinghouses) and their Business Associates processing health information on their behalf.
- When an individual enters their own health information into a personal tool, HIPAA does not apply to that transaction.
However, we treat this data as health-sensitive and apply strong security controls regardless. See our Security page and Privacy Policy for details.
Do not enter another person's health information into the Medicine Reminder tool. The tool is for your own medications only.
5. HIPAA-Aligned SOPs and Templates
Several AVD Clinical templates reference HIPAA compliance (PHI disclosure logs, breach assessment forms, consent withdrawal forms, etc.). These documents are starting frameworks to help your organization build HIPAA-compliant procedures. They are not pre-validated HIPAA compliance tools. Your organization's compliance team, legal counsel, and Privacy Officer must review and adapt these documents before operational use.
Purchasing and using these templates does not make your organization HIPAA-compliant. Compliance requires implementation of administrative, physical, and technical safeguards across your entire organization, executed BAAs with all business associates, staff training, risk assessments, and ongoing audit programs.
6. For Covered Entities — What To Do
If your organization is a HIPAA Covered Entity or Business Associate and you wish to use AVD Clinical tools in workflows that may involve PHI:
- Current platform: Do not enter PHI. Use AVD Clinical only for non-PHI workflows (budget estimation, SOP framework download, regulatory reference).
- Future enterprise platform: A BAA will be available as part of the Enterprise plan. Contact us to be notified when this is available.
- Contact us: Email info@avdclinical.com to discuss your organization's requirements. We can advise on what is and is not appropriate use of the current platform.
7. Security Safeguards Applied to Health-Sensitive Data
Although not required by HIPAA, we apply the following controls to all health-sensitive data (medicine reminder data):
- AES-256 encryption at rest via Supabase
- TLS 1.2+ encryption in transit
- Row-Level Security — data accessible only when authenticated as the account owner
- No sharing with third parties for any commercial or analytical purpose
- User-controlled deletion at any time
See our full Security page for technical details.
8. Questions
For questions about HIPAA compliance, PHI handling, or enterprise BAA inquiries:
AVD Clinical
Email: info@avdclinical.com
Phone: +1 929-502-4973