Resources
HIPAA Privacy Manual (Business Associate)
How Sidepilot uses, discloses and protects PHI as a HIPAA Business Associate.
Security Incident Response Plan
How we detect, contain, investigate and communicate security incidents.
Breach Notification Addendum
Our HIPAA breach assessment and notification procedures for covered-entity customers.
Information Security Policy
The security requirements that govern Sidepilot's people, systems and data.
Risk Assessment Policy
How we identify, rate and treat risks to customer data, including ePHI.
Vendor Management Policy
How we vet, contract with (including BAAs) and monitor vendors and subprocessors.
Data Classification Policy
How we classify data by sensitivity, with PHI treated as our most restricted class.
Data Retention and Disposal Addendum
How long we keep PHI and how we securely return or destroy it.
HIPAA Attestation: No Breach of Unsecured PHI
Signed attestation that Sidepilot has had no breach of unsecured protected health information.
FAQs
Subprocessors
OpenAI
OpenAI is an artificial intelligence research and deployment company focused on building safe and beneficial "artificial general intelligence" (AGI).
Twilio
Twilio is a cloud-based communication platform that allows developers to add voice calls, text messages (SMS), email, and video into their software applications using APIs (Application Programming Interfaces).
Supabase
Managed Postgres database and backend services. Hosts Sidepilot's production application data.
Vercel
Cloud hosting and edge network for Sidepilot's web application.
Google Workspace
Email, identity (SSO) and document collaboration.
Monitoring
Compliance
HIPAA
Sidepilot operates as a HIPAA Business Associate. We maintain a HIPAA security and privacy program with documented policies, annual risk assessments, workforce training, vendor BAAs and continuous control monitoring through Secureframe.
