AlbaUnited States
← Product

Patient information

How Alba handles patient information.

Every vendor in this category writes “HIPAA compliant” on its website. Nobody issues that as a certificate, so the phrase carries whatever the vendor wants it to carry. This page is the specific version: who receives what, which features are switched off because an agreement is missing, and what is not in place yet.

Written for the person at your practice who has to sign off on a vendor. Last reviewed 17 September 2026.

The short version

We are a business associate, and we behave like one.

If your practice is a covered entity, HIPAA requires a written business associate agreement before you hand patient information to any vendor — including us. We sign one. Until it is signed we should not be holding your patients’ information, and we will not start a pilot on a handshake instead.

Below that agreement sits a second obligation that is easier to get wrong: every one of our vendors that could touch your patients’ information needs an equivalent agreement with us. That chain is called flow-down, and it is the part worth checking. Ours is short, on purpose.

Subprocessors

Two, and you can check them.

These are the only third parties that receive patient information in the US configuration.

VendorWhat it receivesWhereAgreement
Microsoft
Azure OpenAI, Azure Speech
Session audio for transcription; transcript text for summarisation. EU region BAA in force
Akamai
Linode, hosting
Everything at rest: the encrypted database and the recording files. EU region BAA in force

That is the whole list. Two other agreements are on file — Qualtrics and AWS — and both cover services this product does not use; they are records, not active relationships. Payment processing runs through Stripe, which receives an account name, an email address, a product name and an amount, and never a patient identifier or any clinical content. No business associate agreement is required for that and we do not claim one.

Where the processing happens. Patient information is processed in the European Union rather than the United States. That is not a HIPAA requirement — HIPAA does not restrict where data is processed — but it is worth knowing before you ask, and it is what our agreement with Microsoft covers.

One case where it matters. Some states restrict offshore processing of Medicaid data, and some health systems restrict it by their own policy regardless of state law. If any of the work you have in mind is Medicaid-funded, or your payer contract carries a data-localisation clause, tell us early rather than at security review. We would rather find out now than waste your time.

Switched off

Features we removed rather than ship without an agreement.

Alba has capabilities that are available elsewhere and are not available here, because the vendor they depend on has no agreement with us. Rather than route your patients’ information through an uncovered third party and mention it in a policy, we disabled them in the software.

Each comes back the same way: the agreement is signed, it is recorded in our vendor inventory, and the feature is re-enabled in a change that says so.

FeatureWhy it is offWhat brings it back
Phone and SMS interviewsWould route the patient’s voice and messages through Twilio, which has no agreement with us.A Twilio agreement covering the specific products, and the account configured for it.
Results by emailOur mail relay is not covered. Elsewhere Alba emails the assessment and the full transcript; here it does not.Moving transactional mail to a covered provider.
Clinical detail in push notificationsNotifications pass through Apple, Google and Expo, and render on lock screens.Nothing — we removed the content instead. The notification says something is ready; the app shows what.
Mailbox searchElsewhere Alba can search a clinician’s mailbox for correspondence with a named patient. That is a deliberate route for patient information into the app and we have not justified it here.A documented consent basis, or the feature stays gone.

What you get instead of an email. When an assessment finishes, the clinician receives a notification saying it is ready and a link. The result, the transcript and the patient identifier stay inside the application behind the login. The patient identifier is also kept out of the subject line, which is the cheapest disclosure in any system of this kind and the hardest to explain afterwards.

Safeguards

What protects the information while we hold it.

  • Encrypted at rest and in transit.Including the recordings, which are the most sensitive artefact in the system. The database is encrypted as a whole, not field by field.
  • A retention clock you set.Audio can be deleted immediately after transcription, or after a period you choose. The deletion is carried out by the system on a schedule, not promised by a policy.
  • Access control and multi-factor authentication.Role-based permissions, sessions that can be revoked per device, and MFA available on every account.
  • A tamper-evident audit trail.Access and changes are written to a hash-chained event log whose integrity can be verified after the fact, so an altered record is detectable rather than merely unlikely.
  • Your material is not training data.Patient recordings, transcripts and notes are not used to train models, ours or anyone else’s.
  • Malware scanning on every upload.Files are scanned before they are accepted, and a scan that fails for any reason rejects the upload rather than letting it through.
Not yet

What we will not claim.

  • SOC 2.Not started. We will not imply otherwise, and we will say so here when it begins.
  • An independent HIPAA audit.Our programme has been assessed internally as substantially aligned and compliance-ready. That is a narrower claim than “compliant”, and we use the narrower one deliberately.
  • FDA clearance.Alba is not a cleared medical device in the United States and is not offered as one. It is designed to stay within the non-device clinical decision support criteria — which is why it will not diagnose, score risk, or recommend treatment.

If you want our internal assessment document and the subprocessor list before you take a call, ask and we will send both.

Verify it

The software will tell you itself.

The capability list above is not a description maintained by hand. It is the configuration the running system enforces, published by the server itself. You can read it without an account:

app.talktoalba.com/compliance/capabilities

Checking the live configuration…

If a feature on the switched-off list ever stops being switched off, that endpoint changes before this page does. We would rather you catch us than trust us.