Readiness, not certification
Compliance readiness starts with the exact data flow.
Readiness is shared among Anivow, each treatment organization, configured vendors, contracts, workforce practices and the specific deployment.
HIPAA
HIPAA readiness
Anivow does not describe itself as “HIPAA certified.” HIPAA does not provide a general government certification for health applications. Readiness depends on implemented safeguards, contracts, configurations and organizational practices.
Contracts
Business Associate role and BAAs
The applicable role and BAA requirements depend on the service and data flow. Current BAA availability is UNKNOWN — requires verification.
Addiction-treatment records
42 CFR Part 2 readiness
Addiction-treatment records can require additional consent and redisclosure controls. Applicability and the product control mapping require qualified legal review.
Other obligations
FTC health-data rules, state privacy laws, breach notification, patient rights and center recordkeeping must be evaluated per deployment.
AI governance
Session Overview displays deterministic patient-shared facts with calculation details and source links. AI does not interpret these records, rank patients or select facts. Generic Program Builder formatting remains separate and requires clinician review.
Compliance review
Bring legal and privacy requirements into the evaluation early.
HIPAA, 42 CFR Part 2, BAAs, retention, AI governance, and vendor posture require deployment-specific review.
Discuss requirements