Cendri Health
Security & Compliance

Built for HIPAA and 42 CFR Part 2 from day one.

The facility's AI, governed so your clinicians stay in control. Cendri runs on AWS and Supabase under signed BAAs with AES-256-GCM field-level encryption. Every governed AI call is checked and logged before a clinician sees the result. Without SUD consent, substance-use information is stripped from anything that leaves your program. Independently pen-tested by Qualysec, April 2026.

HIPAA on AWS

Cendri runs on AWS under a signed BAA. All PHI is processed only by BAA-covered vendors — AWS for hosting, AI models, and transcription; Supabase for the database.

42 CFR Part 2 enforced before anything leaves

Without SUD consent, substance-use diagnoses, MAT medications, screening results, and drug-screen labs are stripped from every payer-facing document. Facility staff retain full access to their own patients' records.

Independent penetration test

Independent pen-test by Qualysec — April 2026, all findings closed at retest. One finding regressed in July and was re-closed on 21 September. Continuous regression testing in production. AWS WAF across all endpoints.

AES-256-GCM field-level encryption

PHI fields — MRN, DOB, NPI, clinical note bodies, and more — encrypted at rest with AES-256-GCM at the field level, not just the volume.

How every AI call is governed

Before any patient data reaches a model, Cendri checks 42 CFR Part 2 consent, confirms the patient belongs to the requesting facility, and allows only approved models running on AWS in US regions under our BAA.

Every clinical statement in a package is checked against the chart.

Every call is logged to tamper-proof storage for six years, and a clinician signs everything before it leaves the facility.

Role-based access, rate limiting, and immutable audit logging at the platform layer. Every PHI access and AI generation is logged to S3 with Object Lock — 6-year retention, tamper-proof.

Survey-ready documentation

Mapped to Joint Commission and CARF standards

Representative examples — the standards library covers more

NPSG.15.01.01Missing or out-of-date C-SSRS flagged before every review
PC.01.02.13Biopsychosocial assessments flagged if missing within 24 hrs
CARF-BH-3.E.1PHQ-9 / GAD-7 flagged when not on file in the last 30 days

Cendri never contradicts your clinician.

Every package requests the level of care your clinician documented. Cendri's own placement opinion never appears in front of a payer — enforced in software, not policy. A tool that told a payer "this patient belonged at a higher level of care" would hand them a denial on your own letterhead.

Incident response & breach notification

Detection

Continuous monitoring and structural RLS policy auditing in production. AWS WAF and CloudWatch alerts flag anomalous access patterns in real time.

Response

A documented escalation path runs from engineering to the security lead to facility compliance. Containment, evidence preservation, and root-cause review begin within hours, not days.

Notification

Affected facilities are notified without unreasonable delay, consistent with HIPAA and 42 CFR Part 2 breach-notification timelines. The full incident and remediation is captured in the audit trail.

Want the security detail reviewed with your team?

We'll walk your compliance and IT leadership through the architecture, the BAA, the pen-test summary, and the governance pipeline.

Talk to our team
Cendri Health

Contact Us

Quick Contact

Follow Us

Cendri is the facility's AI. It reads your whole chart, builds the case for every authorization and review, and flags what the insurer will look for before they ask. Currently live on Kipu and Sunwave, the two largest EHRs for SUD facilities; any EHR with API access can be added during onboarding. Flat per-bed fee, plus a tiered share of results.

© 2026 Cendri Health LLC. All rights reserved.