Compliance

HIPAA Compliance

Nutracie maintains a comprehensive HIPAA compliance program to ensure the security and privacy of protected health information (PHI) processed through our platform.

Business Associate Agreement (BAA)

Nutracie executes Business Associate Agreements with all Enterprise customers who process protected health information through our platform. Our BAA covers all four platform products: NutraDiscover, NutraGenome, NutraOmics, and NutraFold, as well as all associated cloud infrastructure and support services.

To request a BAA, contact our compliance team at compliance@nutracie.com or speak with your dedicated account manager.

Request a BAA

HIPAA Safeguards

Our compliance program implements all required administrative, physical, and technical safeguards under the HIPAA Security Rule.

administrative Safeguards

Designated Security Officer responsible for HIPAA compliance

Workforce training on PHI handling and security awareness

Documented policies and procedures for all PHI access

Regular risk assessments and mitigation plans

Business Associate Agreements (BAA) with all subprocessors

Incident response and breach notification procedures

physical Safeguards

SOC 2 certified data centers with 24/7 physical security

Biometric access controls and visitor management

Environmental controls: fire suppression, climate monitoring

Redundant power and network connectivity

Secure media disposal and sanitization procedures

technical Safeguards

AES-256 encryption for PHI at rest

TLS 1.3 encryption for PHI in transit

Role-based access controls with least-privilege principle

Multi-factor authentication enforced for all PHI access

Comprehensive audit logging of all PHI interactions

Automatic session timeout and idle lockout

Network segmentation isolating PHI processing environments

Intrusion detection and prevention systems (IDS/IPS)

Breach Notification

In the unlikely event of a breach involving PHI, Nutracie will notify affected covered entities within 24 hours of discovery, well within the HIPAA-required 60-day notification window. Our incident response team follows documented procedures to contain, investigate, and remediate any security incident.

Notification will include: a description of the incident, the types of information involved, steps taken to investigate and mitigate, and recommended actions for affected individuals. We will cooperate fully with covered entities in fulfilling their notification obligations to individuals and the HHS Secretary.

Subprocessors

The following subprocessors may process PHI on behalf of Nutracie. All subprocessors have executed BAAs with Nutracie and undergo annual security reviews.

SubprocessorPurposeLocation
Amazon Web ServicesCloud infrastructure, compute, storageUS, EU
Google Cloud PlatformGPU compute, ML training infrastructureUS
SnowflakeData warehousing and analyticsUS
DatadogInfrastructure monitoring (no PHI)US

Questions About HIPAA Compliance?

Contact our compliance team for detailed information or to request documentation.

Contact Compliance Team