Resource · HIPAA framing

AI Leak Guard and HIPAA: a practical safeguard, not a compliance badge

Short answer

We do not claim to make an organization HIPAA compliant. There is no government-issued HIPAA certification for software: HHS does not offer, endorse, or recognize one. Any vendor displaying a HIPAA badge bought it from a private company and it carries no legal weight.

What we do give you: a technical safeguard at the point of disclosure, an audit-friendly mapping to your Security Rule obligations, and a user-held CSV or JSON export as evidence the control is operating.

Why the framing matters

HIPAA compliance is the responsibility of the covered entity and its business associates. It is a program of policies, training, technical safeguards, and administrative controls, all of which the practice implements. No single tool can make an organization compliant. A vendor that claims otherwise is either misinformed or misleading you.

What we do give your compliance advisor

Three concrete artifacts, all on this site, all ungated:

HIPAA Security Rule mapping

Security Rule mapping. The practice's obligations on the left, how the tool supports them on the right.
The practice's obligationHow AI Leak Guard supports it
§164.308(a)(1)(ii)(A) Risk analysisNames workforce use of public AI tools as a risk category most small practices have not documented.
§164.308(a)(1)(ii)(B) Risk managementA technical control at the point of disclosure, reducing the likelihood of impermissible disclosure.
§164.308(a)(5) Security awareness and trainingThe warning is a teaching moment at the moment of risk, not an annual slide deck.
§164.308(a)(1)(ii)(C) Sanction policyThe AUP template gives a written policy staff can be held to.

This is not legal advice, and the practice's risk analysis remains theirs to conduct.

Why we do not sign a BAA

A Business Associate Agreement governs a vendor that creates, receives, maintains, or transmits protected health information on behalf of a covered entity. AI Leak Guard does none of those. The extension never sends patient content to Zabcore, and the website never receives it.

That is not a gap in our compliance posture. It is our compliance posture. There is nothing to sign a BAA over, because there is nothing on our side to protect. See what data we receive for the exact data flow.

What this page is not

  • Not legal advice. Your compliance program is your practice's responsibility.
  • Not a claim of certification. There is no such thing for software under HIPAA.
  • Not a substitute for risk analysis, workforce training, or the other administrative safeguards the Security Rule requires.
Bottom line

AI Leak Guard is a practical safeguard for the disclosure risk that public AI tools introduce. It maps clearly to Security Rule obligations you already carry and gives your practice user-held evidence the safeguard is operating. It does not make you compliant. Nothing does.