HIPAA Compliance
Thyra is built for clinical environments where privacy, security, and reliability are mandatory. This statement describes how Endo Mind, Inc. approaches HIPAA-aligned safeguards for the Thyra platform. It is a summary and does not replace the Business Associate Agreement (BAA) or other customer agreements; where there is a conflict, the executed agreement controls.
How Thyra fits into HIPAA
Customers may be covered entities under HIPAA. When Thyra creates, receives, maintains, or transmits Protected Health Information (PHI) on their behalf, Endo Mind acts as a Business Associate and executes a BAA where required. PHI is used and disclosed only as permitted by the BAA, HIPAA, and applicable law. Thyra does not use PHI for advertising.
Administrative safeguards
- Security governance with access limited to personnel on a need-to-know basis.
- Workforce security training appropriate to role.
- Periodic risk assessments with a remediation process.
- A documented incident response process.
- Vendor management with contractual protections for anyone handling customer content.
Physical safeguards
- Production infrastructure hosted in controlled data centers operated by reputable cloud providers with physical access controls.
- Managed company devices with encryption, strong authentication, and remote wipe where feasible.
Technical safeguards
- Role-based access, least privilege, and strong authentication.
- Encryption in transit using industry-standard protocols; encryption at rest where supported by the underlying infrastructure.
- Audit logs of access and key actions to support monitoring, investigation, and compliance.
- Integrity controls, backups, and transmission security.
Audit trails, breach response, and subcontractors
Thyra is designed so actions are traceable — logins, record access, task routing, and administrative changes may be captured subject to configuration. Suspected security incidents are investigated promptly, and when a BAA applies, breach notification follows the BAA and HIPAA timelines. Subcontractors that may access PHI are required to sign agreements imposing HIPAA-aligned obligations, with access limited to the minimum necessary.
Security reporting
Report suspected security issues to support@thyrahealth.com. Please do not include PHI in email unless necessary. Endo Mind, Inc., Delaware, United States.