HIPAA — protected health information stays on your box.
RailCall's execution model is 127.0.0.1 — the runtime that reads, transforms, and signs PHI runs on the customer's own perimeter. In most deployments RailCall is not a business associate at all under 45 CFR § 160.103 because we never receive PHI. When we do (Enterprise tier with hosted receipt vault), we sign a BAA.
RailCall's local-first + cryptographic-receipt model is the answer to the two things a Covered Entity's legal team actually worries about — data disclosure to a third-party processor and proving what an AI agent did with a patient record. We don't hold the data; we cryptographically prove the actions.
Is RailCall a Business Associate for your deployment?
§164.312 Technical Safeguards — how they map to what RailCall actually does
Evidence + documentation
- Security Risk Analysis — adopted 2026-07-21; refreshed on any material change. Reviewed on request under NDA.
- 66-page compliance evidence package — controls matrix, incident-response plan, data-flow diagrams, subprocessor list. NDA-gated. See the Trust page for the request path.
- Sample signed receipt — see the docs for the receipt shape; every action against PHI in a real deployment emits one of these. Verifiable offline with
railcall verify. - BAA template — aligned to 45 CFR § 164.504(e)(2)(ii). Sent on request under NDA.
Incident + breach notification
When RailCall is a business associate (Enterprise tier), our breach-notification path meets § 164.410: notice to the Covered Entity without unreasonable delay and no later than 60 days after discovery, with the information § 164.410(c) requires. Because our attack surface is the receipt vault (not PHI itself), most incidents would be metadata-level; PHI stays in the customer's perimeter across every plausible incident class.
NDA-gated; sales replies with the mutual NDA + the full documentation set. Reviews from healthcare security teams get priority routing.
Request BAA + evidence bundle