Security & Compliance First AI

AI built to assist your staff — never to replace their judgment

Before we ship any assistant, we ask the same three questions: how it protects resident data, how your staff stay in control of the outcome, and how it holds up against the rules your facility already answers to. Three assistants have met that bar so far — and we hold every future one to the exact same standard, as we grow.

The Short Version

What we promise, in plain terms

Everything is encrypted, in transit and at rest.
On Microsoft Azure infrastructure.
A Business Associate Agreement (BAA) is available on request.
For any facility that needs one for HIPAA.
We tell you exactly who touches your data.
See the vendor list below — no hidden sub-processors.
AI drafts, your staff decides.
We assist, you decide — AI never replaces clinical judgment.
Human in the loop

A typical AI assisted workflow

1

AI drafts from what it hears or reads

A first pass only — never the final record.

2

Staff reviews the draft

Edits, corrects, or discards it — same as reviewing any other note.

3

Staff approves and signs

Approval is attributed to the reviewing staff member, not the AI.

4

We recommend only a reviewed draft is charted

Same record, same audit trail as any other entry.

Security First

What we do — and don't do — with resident data

Resident data access is governed by your EHR. AI Assistants act on behalf of your staff and access resident data during the session only.

HIPAA Compliant Data Access

Resident data access governed through EHR. EHR compliance extended to AI Assistants.

Data stays inside your facility's record

Resident Data stays within EHR. Never copied anywhere else.

AI Assistants operate under BAA

Relic AI runs on Azure - HIPAA Compliant and covered by BAA

Compliance First

Laws We're Tracking, and How They Apply to Us

AI regulation in healthcare is moving fast, and we keep an eye on it so you don't have to track it alone. As of this page's effective date, here's where things stand. We'll keep this list updated as these laws evolve and as new ones take effect. This page is meant to support your own facility's compliance program — it doesn't replace your facility's own legal notice obligations.

Eff. 2026-06-30TrackingColorado SB 24-205

Requires AI developers (like us) to document training data practices, foreseeable risks, and system goals, and to keep that documentation current.

Eff. 2025-01-01AppliesCalifornia AB 3030

Requires a disclaimer on AI-generated patient communications, unless a licensed provider reviews them first.

Eff. 2024-05-01AppliesUtah AI Policy Act

Requires telling patients when they’re interacting with generative AI, for healthcare and other regulated professions.

Under the hood

Models and subprocessors we use

We believe you should know exactly which vendors are involved in handling facility or patient data — not just take our word for it. Here’s the full list:

This list covers every vendor that can see facility or patient data. It doesn't list internal engineering tools that never touch customer data.

Questions or BAA requests?

Facilities and partners with security, compliance, or BAA questions can reach us directly.