Last Updated: March 25, 2026
ProvenIQ Health takes the protection of patient health information seriously. We are designed from the ground up to support HIPAA compliance for our partner practices.
ProvenIQ connects to your EHR via read-only API access. Protected Health Information (PHI) remains in your electronic health record system at all times. We do not store, copy, or transfer identifiable patient records to our servers.
The clinical intelligence ProvenIQ generates is built from de-identified data. We follow the HIPAA Safe Harbor method for de-identification, removing all 18 categories of identifiers specified under 45 CFR 164.514(b)(2) before any data is used in our analytics pipeline.
For practices that require it, ProvenIQ will execute a Business Associate Agreement (BAA) prior to any data integration. This ensures all parties understand their responsibilities for protecting health information under HIPAA.
As the covered entity, your practice maintains responsibility for obtaining appropriate patient consent, managing access to ProvenIQ within your organization, and reporting any suspected security incidents.
For questions about our HIPAA compliance practices or to request a BAA, contact us at compliance@proveniq.health.