For healthcare professionals · HIPAA

AI speed, without a breach notification on someone's terms of service.

Under HIPAA, an impermissible disclosure of PHI to a third party can trigger breach notification duties and civil penalties. Pasting a patient's chart into ChatGPT can be exactly that.

Experience confidential AI
Use cases

The work you've been blocked from doing

Chart summarization

Attach a full patient note and ask for a summary or a differential. Real name, real MRN, full clinical detail, with no redaction step first.

Patient correspondence

Draft after-visit summaries, referral letters and prior-authorization appeals that come back already personalized, because the model saw the actual chart.

Research with sources

Ask the agent to check current literature or guidelines on the web. Every search leaves the machine only after you approve that specific call.

Document intake

Attach labs, imaging reports or intake forms and the agent extracts the text, page by page, including scanned pages it reads with vision.

How it works

Where the chart actually goes

You write the real name and the real MRN. Nothing is swapped for a stand-in, and nothing needs to be, because the only machine that opens the message is sealed hardware.

What you send

"Summarize the chart for Maria Alvarez, MRN 00123456, presenting with intermittent chest pain and shortness of breath."

Who can read it
  • Your device can read it: Plaintext, in a SQLCipher database only your passphrase opens.
  • Amnesia AI®'s gateway cannot read it: Relays ciphertext. It holds no key that decrypts your message.
  • The enclave can read it: Decrypts inside Intel TDX to run the model. Memory is encrypted.
  • The enclave's operator cannot read it: No path to the plaintext, and the reply's report says so.
Message content is encrypted. The tool calls and file paths your agent touches are visible to the gateway: see what we don't hide.
What we can and cannot tell you

The technical facts, not a compliance verdict

What we can state is mechanical: your message is encrypted on your device, Amnesia AI® holds no key that decrypts it, and it is opened only inside an attested enclave whose operator has no path to the plaintext. Each attested reply carries a hardware report you can export and hand to a reviewer.

What we will not state is whether that satisfies any particular HIPAA obligation, or whether a Business Associate Agreement is required for your data flow. That is a determination for your practice and its counsel. Amnesia AI® does not confer HIPAA compliance, and your practice remains responsible for its own obligations.

Other verticals

Same product, different law

Client matters, patient charts, and account holdings are encrypted on your machine and opened only inside the enclave, whichever confidentiality law applies to your work.

Amnesia AI® does not create attorney-client privilege or work-product protection, and does not determine whether information is discoverable. Designed to support data-minimization workflows; it does not itself confer HIPAA, GLBA, or GDPR compliance.

Stop choosing between falling behind and a breach notification.

Attested replies export a signed report a reviewer can check.

Experience confidential AI