HIPAA at RecordX
What "not HIPAA-certified" means
HIPAA does not have a formal certification body. What it does have is a set of obligations for Covered Entities (providers, plans, clearinghouses) and their Business Associates - vendors that touch PHI on their behalf. To use a vendor for PHI legally, a Covered Entity signs a Business Associate Agreement (BAA) with that vendor.
RecordX does not sign a BAA as a default term of service. Recording PHI on the standard RecordX plan is not authorized. If you are a Covered Entity or a Business Associate that needs to route PHI through RecordX, we can scope a paid engagement and sign a BAA - see the next section.
Security controls that already align with the HIPAA Security Rule
Even without a BAA, the controls RecordX runs today map to the Security Rule's technical safeguards. If you are a buyer evaluating fit for a future BAA scope, this is what is in place:
Access control (§164.312(a))
Managed identity through AWS Cognito, unique per-user accounts, session tokens that expire, and internal services scoped by IAM roles.
Audit controls (§164.312(b))
API calls, authentication events, and administrative actions are logged. Access to production systems is audit-logged.
Integrity (§164.312(c))
Storage uses AWS-managed integrity checks. Application changes go through code review before merge.
Person authentication (§164.312(d))
Email + password or Google sign-in via managed identity. Passwords are never stored by RecordX itself.
Transmission security (§164.312(e))
TLS 1.2 or higher for every client connection. Storage access from browsers is via short-lived signed URLs.
Encryption at rest (§164.312(a)(2)(iv))
All audio, transcripts, summaries, and account data encrypted at rest with industry-standard symmetric encryption.
BAA-in-progress: how to request one
For scoped engagements where PHI must be routed through RecordX, we can:
- Provide a controls summary mapped to the HIPAA Security Rule.
- Scope the workflow that will touch PHI (which endpoints, which surfaces, retention needs, deletion posture).
- Negotiate and sign a Business Associate Agreement.
- Provision the account with the terms attached.
Email legal@recordx.io with subject "BAA request" and a short description of the intended use. We respond within two business days.
If you record health conversations without a BAA
Recording your own personal health conversations (a patient recording their own visit for personal reference) is generally not a HIPAA question - HIPAA regulates Covered Entities and their Business Associates, not individual patients. But if you are a clinician, coach, or employer routing patient conversations through RecordX without a BAA, that is a HIPAA gap you own, not one RecordX resolves for you.
Fields where users often bring this up: therapy, medical, coaching. Each of those use-case pages describes a general workflow; none of them constitute a HIPAA-authorized configuration.
Related jurisdictions
If HIPAA is not your jurisdiction, other frameworks may still apply: GDPR in the EU/EEA, Israeli Privacy Protection Law, 5741-1981 in Israel, CCPA in California. See the compliance overview.
Contact us for a security review
For BAA requests: legal@recordx.io. For security questions and controls documentation: security@recordx.io. General: contact form.