Readiness, not certification

Compliance readiness starts with the exact data flow.

Readiness is shared among Anivow, each treatment organization, configured vendors, contracts, workforce practices and the specific deployment.

Status noteThis page is product information, not legal advice or a statement that a specific deployment is compliant.
Readiness, not certificationShared responsibilityLegal review required

HIPAA

HIPAA readiness

Anivow does not describe itself as “HIPAA certified.” HIPAA does not provide a general government certification for health applications. Readiness depends on implemented safeguards, contracts, configurations and organizational practices.

Contracts

Business Associate role and BAAs

The applicable role and BAA requirements depend on the service and data flow. Current BAA availability is UNKNOWN — requires verification.

Addiction-treatment records

42 CFR Part 2 readiness

Addiction-treatment records can require additional consent and redisclosure controls. Applicability and the product control mapping require qualified legal review.

Other obligations

FTC health-data rules, state privacy laws, breach notification, patient rights and center recordkeeping must be evaluated per deployment.

AI governance

Session Overview displays deterministic patient-shared facts with calculation details and source links. AI does not interpret these records, rank patients or select facts. Generic Program Builder formatting remains separate and requires clinician review.

Compliance review

Bring legal and privacy requirements into the evaluation early.

HIPAA, 42 CFR Part 2, BAAs, retention, AI governance, and vendor posture require deployment-specific review.

Discuss requirements