HealixAI Logo

Privacy Policy & AI Disclosures

At HealixAI, operated by Healix AI, Inc. (and affiliated entities including HealixAI, LLC), we are committed to protecting your privacy and ensuring the security of your personal health information. Created by a board-certified physician, we understand the sacred trust between patients and healthcare providers.

Effective Date: April 1, 2026Last Updated: August 1, 2026 (CMS Medicare & HTI-1 Compliant)

1. Health Data & FHIR / Medicare Compliance

HealixAI utilizes the industry standard SMART on FHIR (Fast Healthcare Interoperability Resources) framework and official Medicare API channels to securely connect to your electronic health records and Medicare data. We explicitly request read-only access to the following clinical data scopes:

  • Patient Profile & Demographics (Patient.read)
  • Medications & Prescriptions (MedicationRequest.read)
  • Clinical Conditions (Condition.read)
  • Laboratory & Vitals (Observation.read)
  • Medicare Data (ExplanationOfBenefit.read)
  • Immunizations (Immunization.read)
  • Allergies & Intolerances (AllergyIntolerance.read)
  • Surgical Procedures (Procedure.read)
  • Diagnostic Reports (DiagnosticReport.read)
  • Insurance Coverage (Coverage.read)

We never request write access. HealixAI cannot modify, delete, or create records in your provider's electronic health record system. All FHIR and Medicare API requests are strictly read-only operations.

2. AI Architecture, Model Transparency & Data Usage

HealixAI utilizes specific Artificial Intelligence (AI) and Machine Learning (ML) engines to provide 24/7 conversational navigation and evidence-based clinical guidance. Our AI architecture includes:

Google Gemini 3.1 Live (Vertex AI)Powers live real-time WebRTC conversational voice companion and health navigation dialogue under our signed Google Cloud BAA.
BigQuery Vector SearchIndexes 2.3M+ peer-reviewed PubMed articles (`text-embedding-005`) for sub-150ms peer-reviewed clinical citations.
PyHealth ML EngineNormalizes raw ICD-10/LOINC codes to calculate 30-day readmission risk and polypharmacy safety alerts.

Data Transmitted to AI: HealixAI extracts structured clinical observations, conditions, and medication names before processing. We never send full raw FHIR bundles, Social Security Numbers (SSNs), financial details, or home addresses to AI inference models.

Zero Model Training Guarantee: Your personal health data, Medicare data, and conversations are NEVER used to train public AI models, foundation LLMs, or third-party algorithms. Informed consent is required for all data processing.

3. Voice Streaming & Audio Privacy

"For privacy, all audio streaming happens statelessly over TLS 1.3 encrypted connections under our signed Google Cloud BAA. Our platform does not store raw voice recordings or audio transcripts on translation nodes, which keeps us fully compliant with HIPAA security rules."

4. Responsible AI Disclosure & Error Reporting

While our AI guidance is grounded in peer-reviewed PubMed science and validated clinical guidelines, AI-generated content can occasionally return unexpected outputs. If you observe any abnormal AI output:

  • Contact our AI Safety Officer immediately at ai-safety@healixai.com.
  • Reports are reviewed by medical personnel within 24 hours.
  • Medical Disclaimer: HealixAI guidance does not substitute for professional medical advice. Always consult with a qualified healthcare provider for clinical decisions.

5. Business Transfers & Corporate Reorganization

In the event of a merger, acquisition, corporate reorganization, asset sale, or bankruptcy of Healix AI, Inc.:

  • Users will be notified at least 30 calendar days prior via email and in-app notice of any ownership change.
  • If user information is transferred to an acquiring entity, the acquirer remains bound by the terms of this Privacy Policy.
  • Right to Withdraw Consent: Users maintain the absolute right to revoke consent and request immediate data deletion prior to any business transfer by contacting privacy@healixai.com.

6. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal mandates, CMS regulations, or AI tools.

Notification Procedure: For material policy changes, we will notify users 30 days in advance via email and display a prominent banner upon app launch.

Acceptance Requirement: Users may be required to review and explicitly click to accept the updated policy before continuing service access.

7. Data Retention & Revocation Rights

You have the absolute right to revoke our access to your Electronic Health Records (EHR) and Medicare data at any time directly through your provider portal or Medicare.gov. If you close your HealixAI account, all synchronized data will be cryptographically purged within 30 calendar days.

To request immediate data deletion, contact privacy@healixai.com. We confirm deletion within 5 business days.

8. HIPAA & Security Standards

  • All clinical API requests executed over TLS 1.3 encrypted connections
  • OAuth 2.0 / SMART on FHIR authorization with short-lived access tokens
  • Data encrypted at rest using AES-256 in Google Cloud infrastructure
  • Annual security risk assessments and vulnerability scanning

9. Contact Information & AI Safety Officer

Healix AI, Inc. (and HealixAI, LLC)

Chief Medical Officer & AI Safety Officer: Ricardo Hamilton, MD

Privacy Inquiries: privacy@healixai.com

AI Safety Reporting: ai-safety@healixai.com

Website: www.healixai.com

Questions regarding data security or CMS compliance?