GALEX AI
Security & HIPAA Readiness — Hospital Pilot
Nisimblat Consulting LLC · HIPAA Security Officer: Marco Silva · Effective October 2, 2026
Production deployment involving hospital PHI is subject to completion and verification of applicable
security, contractual, infrastructure and hospital-specific vendor requirements.
🏥 What GALEX AI is — and what it is not
Scope of the platform under review
GALEX AI is an AI-assisted clinical record audit platform designed to identify documentation gaps, potential clinical deviations, patient-safety signals and findings that may warrant review by qualified professionals.
It does not provide medical treatment, does not replace a physician, does not determine that malpractice, negligence or patient harm occurred, and does not replace an organization’s quality, risk or peer review programs or its legal counsel.
✅ Security & HIPAA readiness framework
Documentation and controls prepared for hospital security and vendor review
- ✅Risk Analysis FrameworkFormal security and risk-assessment documentation (45 CFR §164.308(a)(1)(ii)(A))
- ✅HIPAA Security PolicySecurity responsibilities, access controls and safeguards framework
- ✅Privacy Policy — Notice of Privacy PracticesPrivacy and data-protection framework (§164.520)
- ✅Incident Response PlanDetection, containment, investigation and notification procedures
- ✅Disaster Recovery & Contingency PlanRecovery objectives, backup architecture and response procedures
- ✅Patient Authorization WorkflowAuthorization enforced in the pilot environment before any analysis (§164.508)
- ✅Access Control FrameworkAuthentication, authorization and protected report-access procedures
- ✅Audit & Accountability FrameworkAudit logging and security-event accountability procedures
- ✅Business Associate Documentation FrameworkBAA and third-party vendor review documentation
- ✅Designated HIPAA Security OfficerMarco Silva — Nisimblat Consulting LLC
🔐 Technical security controls
Architecture available for hospital security review
Hospital security review: technical, contractual and infrastructure requirements are evaluated as part of pilot onboarding.
📋 Patient authorization — a mandatory system step
HIPAA §164.508 — authorization for use and disclosure of PHI
Patient authorization is not an optional form in GALEX AI. It is enforced by the backend: a signed authorization produces a Consent ID, and an analysis request submitted without a valid Consent ID is refused.
How the workflow runs
- The patient or authorized representative completes and signs the authorization.
- The system records the signature and issues a Consent ID.
- The Consent ID is entered in the GALEX AI panel.
- Clinical records are uploaded.
- Only then does the system run the audit.
What the authorization discloses to the patient
- Records are processed by an AI system (Claude, by Anthropic) operating under a Business Associate Agreement.
- The report is informational and does not constitute medical, legal or professional advice.
- Records are transmitted over TLS encryption.
- The authorization may be revoked at any time, except as to action already taken in reliance on it.
- No service or benefit is conditioned on signing the authorization.
- PHI is retained for six years as required by HIPAA §164.530(j), then securely destroyed.
🤝 Business Associate Agreements
HIPAA §164.308(b)(1) — third parties with access to PHI
GALEX AI maintains a current inventory of every third party that may receive PHI, with the corresponding agreement status reviewed by the Security Officer.
Parties in scope
- Anthropic, PBC (Claude API) — processes the submitted records to generate the analysis. Under the BAA framework, PHI is not used to train models.
- Hosting provider — server infrastructure. Data processing agreement reviewed by the Security Officer.
Terms the BAA framework requires
- PHI used only to provide the contracted service, and as required by law.
- Administrative, physical and technical safeguards per 45 CFR §164.306.
- Reporting of any impermissible use, disclosure or security incident without unreasonable delay and no later than 60 days after discovery.
- The same restrictions flowed down to any subcontractor handling PHI.
- Return or destruction of PHI upon termination, where feasible.
🔒 Privacy — what we collect, how we use it, your rights
Notice of Privacy Practices — HIPAA §164.520
PHI collected
- Medical records, clinical notes, laboratory results, imaging reports, surgical notes and other submitted health documents.
- Patient demographics: full name, date of birth, medical record number or national ID.
- AI-generated forensic analysis reports based on the submitted records.
- Contact information of the authorized requester.
- Authorization records (Consent ID, date signed, relationship to patient).
- Audit trail records (access logs, download logs).
Permitted uses
- Generating the forensic analysis report.
- Delivering the report through the secure panel — reports are not distributed to third parties.
- Audit and compliance logging under §164.312(b).
PHI is not sold, rented or shared for marketing, advertising or any purpose other than providing the requested analysis.
Patient rights
- Access (§164.524) — request a copy of the PHI held; response within 30 days.
- Amendment (§164.526) — request correction of inaccurate PHI.
- Accounting of disclosures (§164.528) — request a list of disclosures made.
- Restriction (§164.522) — request limits on certain uses.
- Revocation — withdraw authorization at any time.
- Complaint — file with us or with HHS Office for Civil Rights at hhs.gov/ocr, without retaliation.
Retention and deletion
PHI and generated reports are retained for six years from creation, as required by HIPAA §164.530(j). On expiration or on a verified deletion request, PHI is securely destroyed: database records deleted, report files removed, backups purged on their next rotation cycle.
Breach notification
If a breach of unsecured PHI occurs, affected individuals are notified within 60 days of discovery, as required by HIPAA §§164.400–414, with a description of what happened, what PHI was involved, the response underway and the steps the individual can take.
🛡 Security policy
45 CFR §164.308 — administrative, physical and technical safeguards
Designated Security Officer (§164.308(a)(2))
Marco Silva is the designated HIPAA Security Officer: implementation of this policy, annual risk analysis, workforce training, incident response coordination and primary point of contact for HIPAA security matters.
Access controls (§164.312(a))
- Access to PHI requires authentication via signed session tokens with bounded expiry.
- Passwords are hashed with bcrypt; plain-text and weakly-hashed passwords are not permitted.
- Administrative credentials are stored in the server environment file, never in application code or version control.
- No shared accounts — each authorized user holds individual credentials.
- MFA for administrative accounts is being implemented prior to commercial hospital deployment.
Audit controls (§164.312(b))
- PHI access events are logged with user, action, record accessed, IP address and UTC timestamp.
- Audit logs are retained six years per §164.530(j) and are not deleted, truncated or altered.
- Log access is restricted to the Security Officer and the system administrator.
Transmission security (§164.312(e))
- All data in transit is encrypted via TLS 1.2+; HTTP requests are redirected to HTTPS.
- PHI transmitted to the AI processing API is sent over TLS.
Encryption at rest (§164.312(a)(2)(iv)) — in progress
Encryption at rest for the database and report files is identified in the Risk Analysis as a control in implementation. Until it is complete, datacenter physical security and access controls mitigate — but do not eliminate — this risk. We state this openly rather than claim a control we have not finished.
Device and media controls (§164.310(d))
- No PHI is stored on portable media, personal devices or local workstations.
- Server access is by SSH key authentication only; password-based SSH is disabled.
- On service termination, the Security Officer verifies secure destruction of PHI before shutdown.
Workforce training (§164.308(a)(5))
- HIPAA Security Awareness training is required before PHI access is granted, and annually thereafter.
- Training covers PHI identification, permitted uses and disclosures, password security, incident reporting and acceptable use.
- Training records are retained six years per §164.530(j).
🚨 Incident response and breach notification
HIPAA §164.308(a)(6) and §§164.400–414
- Identification — within 24 hours. Any suspected security incident or PHI breach is reported immediately to the Security Officer and the Director.
- Containment — within 48 hours. Affected access is revoked, compromised credentials rotated, services isolated where necessary.
- Assessment — within 10 days. The Security Officer applies the four-factor test under §164.402 to determine whether a breach of unsecured PHI occurred.
- Notification — within 60 days. Affected individuals per §164.404; HHS per §164.408; media notification per §164.406 where 500 or more individuals are affected.
- Documentation. Every incident is documented and retained six years.
- Post-incident review. Root cause analysis and remediation plan within 30 days.
♻ Disaster recovery and contingency
HIPAA §164.308(a)(7)
The contingency framework defines backup architecture, recovery objectives and restore testing. Interim operating targets during the pilot are a 48-hour recovery time objective and a 24-hour recovery point objective, with restore procedures tested quarterly once the formal plan is in place.
Reviewing GALEX AI for your institution?
Security, privacy and vendor documentation can be provided for your review as part of pilot onboarding.
Request a hospital security review →
hospitals@galexaiusa.com · Text: +1 (561) 757-8159
ℹ Important notice
This page describes the current hospital pilot security and HIPAA readiness program of GALEX AI. It is not a representation that GALEX AI has been certified by the U.S. Department of Health and Human Services or any governmental agency. Production deployment involving PHI is subject to completion and verification of applicable security and contractual requirements.
Director: Maikel Nisimblat · HIPAA Security Officer: Marco Silva · Privacy contact: hospitals@galexaiusa.com