Built for healthcare from day one. Not bolted on later.

Solafya handles protected health information (PHI) under HIPAA. Every decision we make about how to store, transmit, and process your patients' information is made with audit, encryption, and access control as defaults, not afterthoughts.

Enterprise AI safety & governance

Built with strict clinical guardrails, zero PHI model retention, and evidence-backed reasoning.

Zero PHI model training

AI inference runs through HIPAA-aligned endpoints bound by a Business Associate Agreement. Patient health information is never stored, retained, or used to train public foundation models.

Human-in-the-loop guardrails

AI Suggests. Clinicians Decide. Writing an AI-drafted note into the EHR requires an explicit physician confirmation step. Every note is inserted as preliminary, never auto-signed, and clearly labeled as AI-generated before a physician ever sees it.

Evidence-backed citations

Every clinical summary and differential Lumina generates is cross-referenced against the patient's chart history and cites published clinical guidelines, including PubMed PMID references.

OWASP Top 10 for LLM Applications

Patient chart data is explicitly delimited from clinician instructions in every prompt, with logged detection for injection attempts and per-user rate limits bounding request volume against abuse.

athenaOne Developer Ecosystem PartnerSMART-on-FHIR, standards-based integrationHIPAA & BAA Ready

HIPAA-aligned, with a BAA for every clinic

We sign a Business Associate Agreement (BAA) with every clinic before any patient data flows.

  • Our cloud infrastructure is HIPAA-eligible, and so are all of our subprocessors
  • Patient identifiers are hashed before logging, never written in plaintext

Your patient data is never sent to ChatGPT or other public AI tools

Solafya's AI summaries and trend insights run inside our HIPAA-aligned environment.

  • Patient data is never used to train AI models
  • Every AI suggestion is labeled, cited, and requires physician review before any clinical action
  • Every AI suggestion is audit-logged with two-year retention

Your data is encrypted, always

Patient information is encrypted both while it sits in our systems and while it travels between them.

  • EHR login credentials are encrypted with a clinic-unique key

Who can see what, and when

Access to any part of the system is permission-based. Every clinical action is recorded.

  • Role-based access control, enforced at the organization level
  • Multi-factor authentication on all accounts
  • Staff and customer access are separate, monitored identity pools

It's your data. Always.

Your clinic owns its patient data, end to end.

  • We don't sell it. We don't share it with anyone outside the BAA chain
  • Export on request
  • Deletion on request after your pilot or subscription ends

Where we are, and where we're going

Today

HIPAA-aligned. BAA available with every pilot.

In progress

SOC 2 Type I, targeting Q4 2026.

On our radar

Additional certifications as we grow with our customers.

If something goes wrong

We'll tell you within 72 hours of confirming any security incident affecting your clinic's data, plainly, and with what we're doing about it.

Security questions? Email security@solafya.com. We will respond within one business day.
HIPAA-alignedPatient data encryptedAI suggests, you decideSee our security & compliance →