Last updated: July 31, 2026
HIPAA readiness
EigenH is working toward operational readiness for approved workflows that may involve Protected Health Information or electronic Protected Health Information, often called PHI and ePHI.
HIPAA has no product certification, so we do not describe EigenH as certified under HIPAA and do not make an unconditional compliance claim. Whether HIPAA applies depends on the parties, the data, the workflow, the agreement, and the configured environment.
What has to be true before production PHI
Three things, all of them checkable:
- EigenH has approved the use case and production environment in writing. Approval is specific to a workflow and an environment, not a blanket account-level permission.
- A Business Associate Agreement is in effect where required. This is the “BAA ready” status above — the agreement is available and executed before PHI moves, not after.
- The customer has completed the required security, access, consent, integration, and configuration steps. These are settled during the security review described below.
A customer’s use of EigenH does not make that customer compliant with HIPAA or any other law.
What EigenH is
EigenH AI, Inc. develops administrative workflow software for healthcare practices. EigenH is designed to help authorized teams manage patient calls, appointment requests, follow-up, staff tasks, and related front-desk work.
EigenH is not a healthcare provider, emergency service, medical device, or substitute for licensed clinical judgment.
Administrative AI boundaries
EigenH workflows must not:
- Diagnose a medical or dental condition
- Recommend treatment or medication
- Provide emergency medical triage
- Replace licensed clinical staff
- Make an unreviewed clinical decision
The practice defines escalation paths for urgent, clinical, complex, or out-of-policy situations.
What we review before production
The scope of a security review depends on the approved workflow and deployment. Topics may include:
- The data the workflow needs and data it should not collect
- User roles, permissions, and staff review
- Customer and tenant separation
- Recordings, transcripts, exports, and integration access
- Data transmission, storage, retention, and deletion
- Administrative logging and incident escalation
- Vendors and subprocessors involved in the approved environment
- Customer notification and contractual requirements
This list describes review areas. It does not claim that a named certification, control, recovery target, or service level is available in every deployment. We confirm current evidence during the review.
Customer responsibilities
Organizations using EigenH remain responsible for:
- Determining whether they are a HIPAA Covered Entity or Business Associate
- Providing required patient notices
- Obtaining required consent for calls, SMS, recordings, and automated communications
- Configuring user permissions and approved workflows
- Reviewing agent summaries, actions, and handoffs
- Validating appointment and practice-management system updates
- Following applicable healthcare, privacy, telephony, and professional rules
Data minimization
An administrative workflow should collect only the information needed for the approved task. Patient information, health details, insurance identifiers, and free text do not belong in website analytics or public support channels.
Do not send patient records, medical details, insurance information, or other PHI through the website contact or demo forms.
Request a security, privacy, or contract review
Tell us which workflow and systems you are evaluating. We will confirm the appropriate review path, the materials currently available, and whether a BAA or other agreement applies.
For privacy, security, contractual, or trust questions, contact support@eigenh.ai.
EigenH is operated by EigenH AI, Inc., a Delaware corporation. Its registered office at 131 Continental Dr, Suite 305, Newark, Delaware 19713, United States is provided for corporate identification only and is not a support or operating office.