Compliance
How MedLegal AI handles HIPAA, CCPA, FERPA, GDPR, and state-level privacy law · Last updated April 21, 2026
Summary: MedLegal AI is built for medical-record workflows. Every upload is handled under a Business Associate Agreement. PHI is encrypted at rest and in transit. We never train on your data; our AI provider (Anthropic) operates our account under contractual zero-retention. Retention is configurable by firm; you can purge any case at any time.
1. HIPAA
Business Associate Agreement (BAA)
Every customer uploading PHI is required to execute our BAA before the first upload. The BAA is countersigned at the time of signup and lives at medicalai.law/baa. Key terms:
- We act as a Business Associate as defined in 45 CFR § 160.103.
- Permitted uses: providing the platform services you subscribed to. No other use.
- Subcontractors: we disclose our subcontractor list (Anthropic, AWS, Railway, Stripe, SendGrid) and maintain agreements with each. Contact [email protected] for the current list.
- Breach notification: within 60 days of discovery, per § 164.410.
- Termination: we return or destroy all PHI within 30 days of account termination, at your election.
Technical safeguards
- Transit encryption: TLS 1.2+ (HTTPS) on every inbound and outbound API call. HSTS enforced.
- At-rest encryption: uploads stored in AWS S3 with SSE-S3 (AES-256). Metadata in SQLite on encrypted EBS.
- Access logs: every PHI access logged in
audit_log with user_id, action, timestamp, truncated IP.
- AI provider zero retention: our Anthropic account runs under the zero-data-retention amendment — prompt and response data is not stored beyond the request lifetime, is never used for training, and is never accessible to Anthropic staff.
- PHI not in logs: application logs redact medical record content at capture time.
Administrative safeguards
- Role-based access: admin vs user vs read-only.
- Session timeout: 14 days with activity; sooner on inactivity.
- MFA available (account settings) — required for admin roles.
- Annual workforce HIPAA training for all staff with PHI access.
2. CCPA / CPRA (California)
We treat all California residents' data as if it fell under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA). Where CCPA and HIPAA overlap, we apply the stricter standard.
Consumer rights
- Right to know: export any personal data we hold on you via account settings → Data export, or email [email protected].
- Right to delete: delete any case or account at any time. Deletion cascades across S3 + DB + any derived outputs within 30 days.
- Right to correct: edit profile data in settings; contact us for audit-log corrections.
- Right to opt out of sale: we do not sell personal information. Period.
- Right to limit use of sensitive data: medical records are treated as sensitive; our use is limited to providing the platform features.
California residents can submit verifiable requests via [email protected]. Response within 45 days per CCPA § 1798.130.
3. FERPA (Education records)
FERPA (20 U.S.C. § 1232g) applies when we process student education records at an educational institution. MedLegal AI's primary use case is medical-legal records, not education records. If you are a plaintiff attorney handling a case involving school records (IEP documents, Section 504 plans, disciplinary records from public schools), the following applies:
- We do not directly collect education records from schools; we receive them only when you upload them.
- We do not re-disclose education records to third parties other than the subprocessors required to provide the service.
- Authorized school officials or parents/guardians should contact the school of origin directly for original records — we are not the source of truth.
- For IEPs and special-education records, we recommend you verify the disclosure consent on file at the school before uploading.
4. GDPR (European Economic Area)
Our primary market is US plaintiff firms. We do not actively market to or solicit EU/UK attorneys. If your case involves an EU-resident plaintiff whose medical records you upload, the data transfer is covered by:
- Your own lawful basis under Article 6 (typically legal claims, Article 9(2)(f))
- Standard Contractual Clauses for international transfers to US
- Our BAA extends to GDPR Data Processing Agreement terms on request
EU/UK data subjects can contact [email protected] for data-subject rights (access, rectification, erasure, restriction, portability, objection).
5. State-level summary
Most US states have HIPAA-equivalent or HIPAA-preemptive laws. We comply with both the federal floor and state-specific requirements. Partial list of state laws we've reviewed:
| State |
Law |
Coverage |
| California | CCPA/CPRA | Full — see §2 |
| New York | SHIELD Act | Full (breach notification, safeguards) |
| Texas | TMRPA | Full (Texas Medical Records Privacy Act — supplements HIPAA) |
| Illinois | BIPA | We do not collect biometric identifiers |
| Colorado | CPA | Full — mirrors CCPA for Colorado residents |
| Virginia | VCDPA | Full |
| Washington | My Health My Data Act | Consumer health data: consent-based, we apply |
| Connecticut | CTDPA | Full |
| Utah, Iowa, Indiana, Tenn., Oregon, Montana, Del., N.J., N.H. | State privacy acts | Mirror CCPA treatment |
6. Data retention
Retention is firm-configurable. Defaults:
- Active case data: retained for the life of your subscription
- Closed case data: retained for 7 years (statute of limitations buffer) unless you purge sooner
- Deleted data: purged from S3 and DB within 30 days; backups rolled off within 90 days
- Audit log: 2 years for security-relevant events
Firm admins can change retention policy under Settings → Data retention.
7. Who to contact