Skip to content

Trust Center

Trust by design, not footer boilerplate.

Hygia sits inside a relationship with patients and members. That places privacy, security, transparency and appropriate human involvement inside the product itself, not beside it.

Security, privacy & compliance

Where we stand today.

Healthcare buyers should be able to read this page and know exactly what is asserted and what is confirmed in diligence.

HIPAA

Hygia is designed to operate as a Business Associate to covered entities, under a Business Associate Agreement that governs how protected health information may be used and disclosed.

Information security programme

Hygia maintains administrative, technical and physical safeguards including access control, encryption in transit and at rest, logging and least-privilege access.

SOC 2 / ISO 27001

Certification and audit status is confirmed in writing during diligence rather than asserted on this page. We publish a status only once it is current and verifiable.

Data governance

Data received by Hygia is governed by the agreement with the healthcare organization that authorises it, and is used to support that organization's relationship with the individual.

Certification and audit language on this page is maintained against actual current status and reviewed by legal, privacy and security before any change is published.

Patient data & permissions

In plain English.

What data Hygia may receive, how it arrives, why it is used, who can see it and how authorization works.

What Hygia may receive

Information authorized by the healthcare organization you have a relationship with — which may include demographic, care-plan, medication, appointment or eligibility information — together with what you share in conversation.

How it reaches Hygia

Through secure, authorized integrations and data feeds established with that organization, under agreements that govern permitted use.

Why it is used

To maintain a useful, informed relationship with you: to know what has already happened, to avoid making you repeat yourself, and to help the right person become involved when needed.

Who can access it

Authorized people at the organization responsible for your care, and Hygia personnel with a defined operational need, under least-privilege access controls and logging.

How authorization works

Access follows the authorization framework of the sponsoring healthcare organization. Caregiver and proxy participation requires appropriate authorization.

Your choices

You can ask what Hygia knows, ask for a human, or decline to continue a conversation. Preferences carry forward in the relationship rather than resetting.

AI transparency

What Gia is, and what Gia is not.

People deserve to know when they are speaking with an AI and what its limits are.

Gia is

  • A conversational relationship offered through a healthcare organization.
  • Able to maintain context from prior interactions so conversations continue.
  • Able to help you understand next steps and keep track of what matters.
  • Able to bring an appropriate person into the conversation when needed.

Gia is not

  • A physician, and does not diagnose or replace clinical judgment.
  • An emergency service.
  • A substitute for the people responsible for your care.
  • A system that acts on clinical matters without appropriate human oversight.

Human oversight is a design requirement rather than a safety net. Situations that call for clinical judgment, that involve risk, or that a person asks to escalate are routed to the appropriate human with the relevant context already assembled.

Ask us the hard questions.

Compliance, privacy and security reviews are part of every serious healthcare conversation. We would rather have them early.