Trust
How SmugMe handles protected health information
Security and privacy were part of the platform’s design rather than something added later. Here is what we do, in plain terms.
Highlights
A signed BAA with every healthcare customer
No surprise upgrade tier and no “enterprise plan required” to handle PHI lawfully.
Encryption at rest and in transit
PHI is protected with industry-standard cryptography wherever it is stored or moved.
HIPAA-eligible cloud infrastructure
PHI is hosted on cloud services intended for regulated healthcare workloads, not generic shared hosting.
Access controls and audit logging
Access to PHI is limited by role and recorded to an audit trail so activity can be reviewed.
Per-practice data separation
Your practice’s data is kept separate from every other practice on the platform, with access scoped to your practice.
Subprocessor agreements
We maintain Business Associate Agreements with the subprocessors that handle PHI on our behalf.
PHI stays within covered systems
AI processing happens in our HIPAA-covered environment or with providers under a BAA. PHI is not sent to consumer AI services.
US-based data residency
PHI is stored in US-based data centers.
Security questions
What compliance teams ask
Will you sign our BAA or yours?
SmugMe signs a Business Associate Agreement with every healthcare customer. Write to hello@smugme.ai to review the terms.
Does the website collect patient information?
No. This website only collects practice and contact details on the application form. Please never include patient information in it.
SmugMe does the work. You take the credit.
We are working with a small group of independent practices before public launch. Founding practices get founder-level onboarding, a say in what we build next, and locked-in pricing. Bring us the workflow that costs your staff the most time.