> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usefini.com/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA and BAAs

> Fini is HIPAA-compliant with a Business Associate Agreement available for enterprise customers; how to request a BAA and how to configure your agent when conversations may contain protected health information.

export const ChecklistMeter = ({title = "Checklist", items = [], results = {}, disclaimer}) => {
  const FV = {
    lime: "#C3EE5E",
    ink: "#131415",
    line: "rgba(127,127,127,0.28)",
    soft: "rgba(127,127,127,0.07)",
    softer: "rgba(127,127,127,0.04)",
    muted: "rgba(127,127,127,0.95)",
    pass: "#C3EE5E",
    warn: "#FFB020",
    fail: "#FF4D4D",
    radius: 14
  };
  const fvCard = {
    border: `1px solid ${FV.line}`,
    borderRadius: FV.radius,
    padding: 18,
    margin: "20px 0",
    background: FV.softer
  };
  const fvChip = active => ({
    border: `1px solid ${active ? FV.lime : FV.line}`,
    background: active ? FV.lime : "transparent",
    color: active ? FV.ink : "inherit",
    borderRadius: 999,
    padding: "6px 12px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer",
    lineHeight: 1.2
  });
  const fvBtn = primary => ({
    border: `1px solid ${primary ? FV.lime : FV.line}`,
    background: primary ? FV.lime : "transparent",
    color: primary ? FV.ink : "inherit",
    borderRadius: 10,
    padding: "7px 14px",
    fontSize: 13,
    fontWeight: 600,
    cursor: "pointer"
  });
  const fvLabel = {
    fontSize: 11,
    fontWeight: 700,
    letterSpacing: "0.08em",
    textTransform: "uppercase",
    opacity: 0.6,
    marginBottom: 8
  };
  const [on, setOn] = useState(() => items.map(() => false));
  const n = on.filter(Boolean).length;
  const reqMissing = items.some((it, i) => it.required && !on[i]);
  const pct = items.length ? Math.round(n / items.length * 100) : 0;
  const msg = n === items.length ? results.complete : reqMissing && results.missingRequired ? results.missingRequired : results.partial;
  return <div style={fvCard}>
      <div style={{
    display: "flex",
    justifyContent: "space-between",
    alignItems: "baseline"
  }}>
        <div style={fvLabel}>{title}</div>
        <div style={{
    fontSize: 13,
    fontWeight: 700
  }}>{n} / {items.length}</div>
      </div>
      <div style={{
    height: 8,
    borderRadius: 999,
    background: FV.soft,
    overflow: "hidden",
    marginBottom: 12
  }}>
        <div style={{
    width: `${pct}%`,
    height: "100%",
    background: FV.lime,
    transition: "width .3s"
  }} />
      </div>
      {items.map((it, i) => <label key={i} style={{
    display: "flex",
    gap: 10,
    alignItems: "flex-start",
    padding: "8px 4px",
    borderTop: i ? `1px solid ${FV.line}` : "none",
    cursor: "pointer"
  }}>
          <input type="checkbox" checked={on[i]} onChange={() => setOn(o => o.map((v, j) => j === i ? !v : v))} style={{
    marginTop: 3,
    accentColor: FV.lime
  }} />
          <span style={{
    fontSize: 14,
    lineHeight: 1.5
  }}>
            {it.label}{it.required && <span style={{
    fontSize: 11,
    fontWeight: 700,
    marginLeft: 6,
    opacity: 0.6
  }}>REQUIRED</span>}
            {it.detail && <span style={{
    display: "block",
    fontSize: 12.5,
    opacity: 0.65
  }}>{it.detail}</span>}
          </span>
        </label>)}
      {msg && <div style={{
    marginTop: 12,
    fontSize: 13.5,
    padding: "10px 12px",
    borderRadius: 10,
    background: n === items.length ? "rgba(195,238,94,0.16)" : FV.soft
  }}>{msg}</div>}
      {disclaimer && <div style={{
    fontSize: 12,
    opacity: 0.6,
    marginTop: 8
  }}>{disclaimer}</div>}
    </div>;
};

Fini (usefini.com) is HIPAA-compliant, with a Business Associate Agreement (BAA) available for enterprise customers through your Fini account team, typically in about one week. Put the BAA in place before your agent handles protected health information (PHI), then use the configuration on this page so your agent handles PHI only where it needs to and routes clinical questions to people.

HIPAA compliance is shared. Fini is responsible for how its platform stores, protects and processes data as your business associate. You are responsible for what you send to Fini, which conversations the agent answers, and how your workspace is configured. This page covers both halves.

```mermaid theme={null}
---
title: BAA path and who is responsible for what
---
flowchart TD
    ASK["Ask for a BAA<br/>through your Fini account team"] --> SIGN["Review and sign<br/>Fini template or yours · about one week"]
    SIGN --> CONFIG["Configure and test<br/>test workspace or test data"]
    CONFIG --> LIVE["Connect channels with<br/>real patient conversations"]

    LIVE --> FINI
    LIVE --> YOU

    subgraph FINI["FINI, AS YOUR BUSINESS ASSOCIATE"]
        F1["AES-256 at rest · TLS 1.2+"]
        F2["No foundation-model training<br/>on customer data"]
        F3["US or EU residency"]
        F5["Automatic masking of sensitive data<br/>transcripts · Inbox · AI Steps"]
        F4["72-hour breach notice<br/>30-day subprocessor notice"]
    end

    subgraph YOU["YOUR TEAM"]
        Y1["Send minimum necessary data"]
        Y2["Keep PHI values out of replies"]
        Y3["Route clinical questions to people"]
        Y4["Control dashboard and API access"]
        Y5["Delete on request, test every change"]
        Y6["BAAs with your other vendors"]
    end

    classDef source fill:#F7F7F7,color:#131415,stroke:#E8E8E8
    classDef agent fill:#131415,color:#FFFFFF,stroke:#131415,stroke-width:3px
    classDef surface fill:#FFFFFF,color:#131415,stroke:#131415
    classDef human fill:#C3EE5E,color:#131415,stroke:#131415,stroke-width:2px

    class ASK,SIGN,CONFIG,LIVE surface
    class F1,F2,F3,F4,F5 agent
    class Y1,Y2,Y3,Y4,Y5,Y6 human
```

## What Fini provides

| Area | Fini position |
| - | - |
| HIPAA | HIPAA-compliant handling of customer data; BAA-eligible for enterprise customers |
| Encryption | AES-256 at rest, TLS 1.2+ in transit |
| Model training | Fini does not use customer data, including PHI, to train foundation models. Any per-customer learning happens only inside that customer's environment and only with their written authorization. LLM subprocessors are contractually barred from training on it. |
| Masking | Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps |
| Residency | Your designated region: United States or European Union. With EU data residency, data is stored and processed in the EU. |
| Breach notification | Within 72 hours under the [DPA](https://www.usefini.com/security/data-processing-addendum) |
| Subprocessors | Google Cloud (including Gemini), Microsoft Azure, Supabase, OpenAI, Anthropic, PostHog, Sentry, Stripe, Linear, Google (email) and Langfuse, with purposes in [Data handling](/en/security/data-handling#subprocessors) and 30 days' notice of changes under the [DPA](https://www.usefini.com/security/data-processing-addendum) |
| Supporting evidence | SOC 2 Type II and ISO/IEC 27001:2022 reports, pen-test report, policies: request through the [Trust Center](https://security.usefini.com/) |

## Request a BAA

Enterprise customers are BAA-eligible. Fini can sign its own BAA template or your organization's BAA, and typical turnaround is about one week.

<Steps>
  <Step title="Tell your Fini account team you need a BAA">
    Request the BAA through your Fini account team, and say which workspace and agents will handle PHI. Say whether you want to use Fini's template or your own.
  </Step>

  <Step title="Review and sign">
    Review the BAA alongside the [Data Processing Addendum](https://www.usefini.com/security/data-processing-addendum) with your privacy or compliance team. Plan for about one week from request to signature.
  </Step>

  <Step title="Configure before go-live">
    Apply the recommendations below in a test workspace or with test data, run the Test Suite, and only then connect channels that carry real patient conversations.
  </Step>
</Steps>

## What you are responsible for

The BAA covers Fini's obligations. These recommendations cover yours. None of them is legal advice; your compliance team decides what your use of Fini requires.

### Send only the data the agent needs

The agent sees whatever your knowledge sources, User Attributes and connected channels give it. Apply minimum necessary at the source:

* **User Attributes.** Expose only the fields a workflow actually uses (plan, appointment status, device sync state). Don't return diagnosis codes, clinical notes or full medical history from your attributes endpoint because they might be useful someday. See [Attributes](/en/api-reference/attributes).
* **Knowledge sources.** Train the agent on policies, help articles and procedures, not on documents that contain patient records. Review what you sync from Google Drive, Notion or file uploads. See [Knowledge sources](/en/knowledge/sources).
* **Actions.** Scope each Action to one job, and keep destructive Actions behind confirmation steps in the Rulebook. See [Actions](/en/api-reference/actions).

### Keep PHI values out of replies

Fini automatically masks sensitive data, including card numbers and health details, everywhere it stores conversation data (transcripts, Inbox and AI Steps traces). Fields you hide from the AI are also redacted in AI Steps. Design workflows so the agent never asks for health details it doesn't need. Guardrails add a layer on top for what the agent says. Add a **Confidential attributes** guardrail and select the attribute keys whose values must never appear in a reply, such as date of birth, member ID or medical record number. The check matches the actual values for that customer; it is not blanket detection of all personal data, so pair it with a **Custom rule** describing what the agent must never disclose. See [Guardrails](/en/configuration/guardrails).

### Route clinical questions to people

Fini is a support agent, not a clinical tool. Layer these controls so medical questions go to your team instead of getting an AI answer:

* Add clinical advice, symptoms and medication questions to the *Escalation Topics* subsection of the Planning Prompt's **Knowledge Search – Decision Logic** section. Medical emergencies and self-harm are already in Fini's default triggers. See [Prompts](/en/configuration/prompts#controlling-when-the-agent-escalates).
* Add a **Custom rule** guardrail that fails any reply giving diagnosis, dosage or treatment guidance.
* Use a Reply Rule on the **Internal Comment** card for clinical tag values, so even a misrouted conversation produces a note for your team rather than a customer-facing reply. See [Reply Rules](/en/automations/reply-behavior).

### Control who can see conversations

* Turn on single sign-on (Okta, Google, Slack or Microsoft Entra ID) and give dashboard access only to the staff who need it. With [Okta SSO](/en/sso-login), removing someone from the SAML app removes their access.
* Use one [API key](/en/deploy/api-keys) per integration, with `read` only where possible, and revoke keys when an integration or teammate leaves.
* Inbox mirrors conversations from your connected helpdesk, including human-agent replies and internal notes. Anyone with dashboard access can see them, so treat dashboard access like helpdesk access.

### Handle deletion and access requests

When a patient asks for their data to be deleted, delete the matching conversations with the [Delete conversation](/en/api-reference/delete-conversation) or [Bulk delete conversations](/en/api-reference/bulk-delete-conversations) endpoints, and delete the source record in your helpdesk too. See [Data handling](/en/security/data-handling#retention-and-deletion) for retention settings. You set your own retention period, and deletion removes all data.

### Test before you ship

Create test cases from clinical and PHI-sharing conversations that use synthetic data, and link them to a criteria group with an AI judgement that the agent declines medical advice and doesn't disclose PHI, plus an exact check for the handoff. Run them after every prompt, knowledge or rule change. See [Test Suite](/en/testing/test-suite).

### Cover the rest of your stack

Fini connects to your helpdesk, telephony and messaging tools. Your BAAs with those vendors, and your own HIPAA program, are outside Fini's BAA.

<ChecklistMeter
  title="Before PHI reaches Fini"
  items={[
{ label: "BAA signed with Fini", detail: "Requested through your Fini account team; about one week.", required: true },
{ label: "User Attributes expose only the fields workflows use", detail: "No diagnosis codes, clinical notes or full medical history." },
{ label: "Knowledge sources contain policies and procedures, not patient records" },
{ label: "Confidential attributes guardrail set for PHI attribute keys", detail: "Paired with a Custom rule describing what the agent must never disclose." },
{ label: "Clinical advice, symptoms and medication questions added as Escalation Topics" },
{ label: "Custom rule guardrail fails diagnosis, dosage or treatment guidance" },
{ label: "Reply Rule sends clinical tag values to Internal Comment" },
{ label: "SSO on, with only staff who need dashboard access assigned" },
{ label: "One API key per integration, read-only where possible" },
{ label: "Test Suite cases for clinical and PHI-sharing conversations pass" },
{ label: "BAAs in place with your helpdesk, telephony and messaging vendors" }
]}
  results={{
complete: "Every item on this page is covered. Have your compliance team review the configuration before you connect live channels.",
partial: "Finish the remaining items, in a test workspace or with test data, before connecting channels that carry real patient conversations.",
missingRequired: "Put the BAA in place before your agent handles PHI."
}}
  disclaimer="Indicative only, not legal advice. Your BAA and your compliance team's requirements are binding."
/>

## Related

<CardGroup cols={2}>
  <Card title="Healthcare setup" icon="hospital" href="/en/industry-setup/healthcare">
    Recommended agent configuration for health and health-tech support teams.
  </Card>

  <Card title="Data handling" icon="database" href="/en/security/data-handling">
    Residency, encryption, retention, deletion and DPA terms.
  </Card>

  <Card title="Guardrails" icon="shield-check" href="/en/configuration/guardrails">
    Confidential attributes, banned terms and custom rules.
  </Card>

  <Card title="Security overview" icon="shield-halved" href="/en/security/overview">
    Fini's full security posture and how to request reports.
  </Card>
</CardGroup>


## Related topics

- [Setting up Fini for healthcare](/en/industry-setup/healthcare.md)
- [Data handling, residency and model training](/en/security/data-handling.md)
- [SOC 2 Type II and ISO 27001](/en/security/soc2-iso27001.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.