Built for HIPAA and 42 CFR Part 2 from day one.
The facility's AI, governed so your clinicians stay in control. Cendri runs on AWS and Supabase under signed BAAs with AES-256-GCM field-level encryption. Every governed AI call is checked and logged before a clinician sees the result. Without SUD consent, substance-use information is stripped from anything that leaves your program. Independently pen-tested by Qualysec, April 2026.
HIPAA on AWS
Cendri runs on AWS under a signed BAA. All PHI is processed only by BAA-covered vendors — AWS for hosting, AI models, and transcription; Supabase for the database.
42 CFR Part 2 enforced before anything leaves
Without SUD consent, substance-use diagnoses, MAT medications, screening results, and drug-screen labs are stripped from every payer-facing document. Facility staff retain full access to their own patients' records.
Independent penetration test
Independent pen-test by Qualysec — April 2026, all findings closed at retest. One finding regressed in July and was re-closed on 21 September. Continuous regression testing in production. AWS WAF across all endpoints.
AES-256-GCM field-level encryption
PHI fields — MRN, DOB, NPI, clinical note bodies, and more — encrypted at rest with AES-256-GCM at the field level, not just the volume.
How every AI call is governed
Before any patient data reaches a model, Cendri checks 42 CFR Part 2 consent, confirms the patient belongs to the requesting facility, and allows only approved models running on AWS in US regions under our BAA.
Every clinical statement in a package is checked against the chart.
Every call is logged to tamper-proof storage for six years, and a clinician signs everything before it leaves the facility.
Role-based access, rate limiting, and immutable audit logging at the platform layer. Every PHI access and AI generation is logged to S3 with Object Lock — 6-year retention, tamper-proof.
Survey-ready documentation
Mapped to Joint Commission and CARF standards
Representative examples — the standards library covers more
Cendri never contradicts your clinician.
Every package requests the level of care your clinician documented. Cendri's own placement opinion never appears in front of a payer — enforced in software, not policy. A tool that told a payer "this patient belonged at a higher level of care" would hand them a denial on your own letterhead.
Incident response & breach notification
Detection
Continuous monitoring and structural RLS policy auditing in production. AWS WAF and CloudWatch alerts flag anomalous access patterns in real time.
Response
A documented escalation path runs from engineering to the security lead to facility compliance. Containment, evidence preservation, and root-cause review begin within hours, not days.
Notification
Affected facilities are notified without unreasonable delay, consistent with HIPAA and 42 CFR Part 2 breach-notification timelines. The full incident and remediation is captured in the audit trail.
Want the security detail reviewed with your team?
We'll walk your compliance and IT leadership through the architecture, the BAA, the pen-test summary, and the governance pipeline.
Talk to our team