HIPAA Compliant

HIPAA Compliance

The ActiPatch® Bioelectric Pain Management Platform from Electrome Corporation is built to meet the requirements of the Health Insurance Portability and Accountability Act (HIPAA), including the Privacy, Security, and Breach Notification Rules.

Where HIPAA Applies in Our Services

Electrome acts as a Covered Entity for the patient-facing services we operate directly (such as support for prescription fulfillment of RecoveryRx®) and as a Business Associate when we provide provider services to a healthcare provider, clinic, or health system that is itself a Covered Entity.

  • ActiPatch® over-the-counter (OTC): Self-reported pain tracking and device-usage data submitted through the ActiPatch™ Patient portal (self-service tier) are classified as PII (not PHI) while the user is a self-service consumer. This data becomes PHI when the user completes clinical onboarding (signs a HIPAA authorization) and the data is associated with provider-directed use of a prescription device.
  • RecoveryRx® (Rx): Prescription, diagnosis, and clinician communication data are full PHI subject to all HIPAA rules.
  • Provider services: Operate under a signed Business Associate Agreement with each clinic or provider organization.

Encryption Everywhere

All Protected Health Information (PHI) collected through ActiPatch®, Clinical AI Concierge, and connected ActiPatch® / RecoveryRx® session data is encrypted with AES-256 at rest and TLS 1.2+ in transit.

Role-Based Access

Patient (self-service and clinical tiers), provider, retailer, affiliate, and investor portals are isolated. Only the patient's authorized care team and Electrome staff with a documented need-to-know can access PHI. Self-service wellness data is PII, not PHI.

Business Associate Agreements

We maintain signed BAAs with every vendor that may touch PHI on our behalf, including hosting, email, scheduling, analytics, and pharmacy fulfillment partners for RecoveryRx®.

Breach Detection & Notification

24/7 monitoring, audit logging, and a written incident-response plan. Affected individuals, HHS, and (where required) media are notified within HIPAA Breach Notification Rule timeframes.

HIPAA Safeguards

Administrative Safeguards
  • Designated Privacy Officer and Security Officer
  • Annual workforce HIPAA training and attestation
  • Documented risk analysis and risk-management program
  • Sanction policy for workforce violations
  • Disaster-recovery and contingency planning
  • Vendor due diligence prior to BAA execution
Physical Safeguards
  • SOC 2 Type II hosting facilities (AWS) with controlled access
  • Workstation-use and clean-desk policies for staff
  • Encrypted laptops and removable media
  • Documented secure-disposal procedures for hardware
Technical Safeguards
  • Unique user IDs and MFA for all workforce and clinician accounts
  • Automatic session timeout and re-authentication
  • AES-256 encryption at rest, TLS 1.2+ in transit
  • Tamper-evident audit logs of PHI access and changes
  • Integrity controls and database backups
  • Network segmentation between portals and databases
  • Continuous vulnerability scanning and patch management

Your Rights Under HIPAA

If you are a patient of a healthcare provider that uses Clinical AI Concierge, or you receive RecoveryRx® through our platform, you have the following rights regarding your Protected Health Information:

  • Right to Access: Receive an electronic or paper copy of your designated record set.
  • Right to Amend: Request corrections to inaccurate or incomplete records.
  • Right to an Accounting of Disclosures: Request a list of certain disclosures of your PHI in the prior 6 years.
  • Right to Restrict: Ask us to limit certain uses or disclosures.
  • Right to Confidential Communications: Request that we communicate with you by alternative means or at alternative locations.
  • Right to File a Complaint: File a complaint with us or with the U.S. Department of Health & Human Services Office for Civil Rights without retaliation.

Post-Quantum Cryptography Roadmap

Electrome is actively exploring FIPS 140-3 certified, post-quantum safe cryptography for data-in-motion, targeted for implementation in 2026. FIPS 140-3 is the U.S. federal cryptographic module standard published by the National Institute of Standards and Technology (NIST) and is recognized internationally (via ISO/IEC 19790) as the benchmark for validated cryptographic implementations used by regulated industries, including healthcare.

Today, the vast majority of the world's data-in-motion is protected by AES-based symmetric encryption negotiated through RSA and elliptic-curve (ECDH/ECDSA) key exchange. These public-key schemes are mathematically vulnerable to a sufficiently large, fault-tolerant quantum computer running Shor's algorithm, and symmetric keys face an effective halving of their security margin under Grover's algorithm. This creates a real-world "harvest now, decrypt later" risk: data intercepted today can be stored and decrypted years from now once quantum hardware matures.

The solution we are bringing in goes beyond swapping in NIST's post-quantum primitives (e.g., ML-KEM / ML-DSA, formerly CRYSTALS-Kyber and CRYSTALS-Dilithium). It is engineered so that intercepted ciphertext contains no exploitable mathematical relationship to the underlying plaintext or to the session keys. In practical terms, even stolen traffic cannot be reversed by Shor's, Grover's, or any currently known cryptanalytic attack — and remains resistant to future many-qubit quantum computers — because there is nothing in the captured bytes for those algorithms to solve.

We have already identified the world's leading provider of this technology. A proof-of-concept / pilot deployment is scheduled to go live in our sandbox environment in Q3 2026, ahead of broader rollout across PHI-bearing services.

Business Associate Agreement (BAA)

Healthcare providers, clinics, and health systems subscribing to Clinical AI Concierge are required to execute Electrome's standard BAA before PHI is exchanged. To request a copy of our BAA, contact our Privacy team.

Questions About HIPAA Compliance?

Contact our Privacy Officer for any questions about our HIPAA practices, to request a BAA, or to exercise your rights.