The 4-Layer Compliance Stack

Most AI research tools weren't built for HIPAA. We were.

Healthcare buyers have spent two years trying to retrofit consumer-research tools for regulated environments. Carevoices was purpose-built for healthcare from day one — with the 4-Layer Compliance Stack pharma and hospital procurement actually requires.

BAA on every healthcare engagement
HIPAA Safe Harbor de-identification
US data residency
Verified clinician on a Carevoices research interview
Live
carevoices.health/dashboard
Study Dashboard 3 Active
0
BAA coverage
▲ 2.1%
0
HIPAA identifiers redacted
▲ 3.5%
0
Data residency
▼ 1.2%
Response Trend 7 days
Choose study type
Buying Process
Message Validation
Concept Testing
Advisory
Tracker
Workforce
US Data residency ▲ 2.1%
78% Complete
Live
The 4-Layer Compliance Stack

Compliance is the wedge, not an afterthought

Available today on every healthcare engagement, included in every contract. The four layers compound — together they form the procurement-cleared compliance posture that legacy AI research tools structurally cannot match.

01

BAA on every healthcare engagement

We sign a Business Associate Agreement with every healthcare customer. Standard, included in every contract for healthcare engagements. Available on request before you sign. Custom BAA terms accommodated when your legal team needs them. Audit rights and breach notification provisions match HHS guidance.

02

PHI-safe transcripts

Your interview data is never used to train models. Never logged for analytics. Never shared with third parties. Pipeline is purpose-built for HIPAA-grade handling — not retrofit from a consumer-research stack. AI moderator processes audio and video without persistent storage of raw PHI. Customer data is firewalled from any model training pipelines.

03

De-identification by default

Every transcript we deliver has identifiers stripped using HIPAA Safe Harbor methodology. All 18 HIPAA identifiers automatically detected and redacted before transcripts reach your team. Custom identifier rules per study. Re-identification key held by Carevoices under BAA, never shared. Expert determination de-identification available on request.

04

US data residency

All data stored, processed, and transmitted within US AWS and GCP regions. Confirmed in writing in your contract. We do not route data through international processing. Backups also US-region locked. No cross-border data transfers, even for AI processing. Region commitments included in the BAA appendix.

In progress (available 2026)

  • SOC 2 Type II audit (in evidence-collection phase)
  • Letter of audit attestation available on request to qualified prospects under NDA

On the roadmap

  • HITRUST CSF certification (target: 2027)
  • ISO 27001 certification (target: 2027)
  • 21 CFR Part 11 capability for regulated submissions (target: 2027)

What we don't claim

We will not claim certifications we don't yet hold. If your procurement requires a certification we don't have, talk to us — we'll tell you the timeline and offer a documented compensating control if appropriate.

Compliance Reference Library

Deep-dive guides for procurement and compliance teams

The detailed methodology, checklists, and statutory references behind each layer of the compliance stack. Written for pharma compliance, hospital legal, and procurement teams running vendor reviews.

Frequently asked compliance questions

What pharma and hospital compliance teams ask

The AI moderator conducts voice or video interviews with participants. We treat this as third-party-conducted research. Carevoices is the entity conducting the interview; the customer is the entity receiving de-identified outputs. This separation matches the HIPAA structure for third-party research vendors.
Our identifier-stripping pipeline catches all 18 HIPAA identifiers in transcripts before delivery. If a participant says "I was diagnosed with [condition] at [hospital] on [date]," the de-identified transcript will have hospital and date redacted. The condition itself remains (qualitative content; not an identifier).
Audio recordings are stored under our BAA, access-controlled, and never delivered to customers in raw form unless explicitly contracted. The default deliverable is the de-identified transcript. Raw audio access requires a separate contract amendment with explicit consent and additional compliance terms.
No. Customer interview data is firewalled from any model training pipelines. Our AI moderator uses base models from Anthropic, OpenAI, and Google with explicit no-training contractual terms — your data is not used to improve their models either.
Yes. Customer audit rights are included in our BAA. Annual SOC 2 Type II reports (when available) shared under NDA. Specific technical questions answered by our compliance team during procurement.
When you pay an HCP an honorarium for participating, that may constitute a transfer of value reportable under the Physician Payments Sunshine Act. Default-blinded studies (most market research) typically don't trigger sponsor reporting because the sponsor never learns participant identity. For unblinded engagements (advisory boards), we provide CMS-format export data — NPI, license, specialty, address — for your sponsor's filing. Built into the panelist intake by design.
US-only at present. If your engagement requires EU data residency (e.g., EU-based clinicians or patients), we offer a DPA with US-based processing under SCCs (Standard Contractual Clauses). EU-region data residency is on the 2027 roadmap.
We will not claim certifications we don't yet hold. SOC 2 Type II is in evidence-collection phase. HITRUST and ISO 27001 are roadmap items. If your procurement requires a certification we don't have, talk to us — we'll tell you the timeline and offer a documented compensating control if appropriate.
Ready to talk compliance?

Get a demo

Bring your compliance team on the call. We walk through BAA terms, identifier stripping methodology, US data residency, and Sunshine Act handling on the demo.

With your compliance team welcome

Walk through BAA terms, identifier stripping, and US data residency on the call

For enterprise + RFP

Multi-year subscriptions, RFP responses, or top-20 pharma procurement