Compliance

How MedLegal AI handles HIPAA, CCPA, FERPA, GDPR, and state-level privacy law · Last updated April 21, 2026

Summary: MedLegal AI is built for medical-record workflows. Every upload is handled under a Business Associate Agreement. PHI is encrypted at rest and in transit. We never train on your data; our AI provider (Anthropic) operates our account under contractual zero-retention. Retention is configurable by firm; you can purge any case at any time.

1. HIPAA

Business Associate Agreement (BAA)

Every customer uploading PHI is required to execute our BAA before the first upload. The BAA is countersigned at the time of signup and lives at medicalai.law/baa. Key terms:

Technical safeguards

Administrative safeguards

2. CCPA / CPRA (California)

We treat all California residents' data as if it fell under the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA). Where CCPA and HIPAA overlap, we apply the stricter standard.

Consumer rights

California residents can submit verifiable requests via [email protected]. Response within 45 days per CCPA § 1798.130.

3. FERPA (Education records)

FERPA (20 U.S.C. § 1232g) applies when we process student education records at an educational institution. MedLegal AI's primary use case is medical-legal records, not education records. If you are a plaintiff attorney handling a case involving school records (IEP documents, Section 504 plans, disciplinary records from public schools), the following applies:

4. GDPR (European Economic Area)

Our primary market is US plaintiff firms. We do not actively market to or solicit EU/UK attorneys. If your case involves an EU-resident plaintiff whose medical records you upload, the data transfer is covered by:

EU/UK data subjects can contact [email protected] for data-subject rights (access, rectification, erasure, restriction, portability, objection).

5. State-level summary

Most US states have HIPAA-equivalent or HIPAA-preemptive laws. We comply with both the federal floor and state-specific requirements. Partial list of state laws we've reviewed:

State Law Coverage
CaliforniaCCPA/CPRAFull — see §2
New YorkSHIELD ActFull (breach notification, safeguards)
TexasTMRPAFull (Texas Medical Records Privacy Act — supplements HIPAA)
IllinoisBIPAWe do not collect biometric identifiers
ColoradoCPAFull — mirrors CCPA for Colorado residents
VirginiaVCDPAFull
WashingtonMy Health My Data ActConsumer health data: consent-based, we apply
ConnecticutCTDPAFull
Utah, Iowa, Indiana, Tenn., Oregon, Montana, Del., N.J., N.H.State privacy actsMirror CCPA treatment

6. Data retention

Retention is firm-configurable. Defaults:

Firm admins can change retention policy under Settings → Data retention.

7. Who to contact