Security & compliance

HIPAA-compliant AI for healthcare enterprises

Arkangel AI is ISO 27001:2022 certified. HIPAA compliance and a BAA are available on Enterprise plans, backed by 70+ security controls, penetration testing and continuous monitoring via Vanta.

  • ISO 27001:2022 certified
  • HIPAA and BAA on Enterprise plans

Security at a glance

Arkangel AI is ISO 27001:2022 certified and offers HIPAA compliance and a BAA on Enterprise plans. More than 70 security controls cover infrastructure, data privacy and audit procedures; the platform is penetration tested and monitored continuously via Vanta. Self-serve plans are not covered by HIPAA, so do not enter patient identifiers there.

Certifications and security controls

The same controls protect every plan. Certification details and policies are documented in our public Trust Center.

ISO 27001:2022 certified

Our information security management system is certified to ISO/IEC 27001:2022, the international standard for managing information security risk.

HIPAA compliance and BAA on Enterprise plans

HIPAA compliance and a signed Business Associate Agreement (BAA) are available on Enterprise plans. Contact us about contractual terms before your organization works with protected health information (PHI).

70+ security controls

More than 70 controls cover infrastructure, data privacy and audit procedures.

Penetration testing

The platform is penetration tested to identify and remediate vulnerabilities.

Continuous monitoring via Vanta

Controls are monitored continuously through Vanta and documented in the Arkangel AI Trust Center.

Access control and traceability

Role-based access control, secure development policies, change-management procedures, audit trails and asset-handling controls let teams collaborate across departments with traceability.

Visit the Trust Center

How we handle your data

A plain-language summary of our Privacy Policy as it applies to clinical work. The Privacy Policy is the governing document.

Before you type a patient question

Unless your organization has an Enterprise agreement that covers HIPAA, remove names, record numbers, dates and any other identifiers before you ask Arkangel AI a question.

Self-serve plans (Free, Pro and Team)
Questions and other inputs are not covered by HIPAA. You are responsible for making sure they contain no protected health information (PHI) and nothing that violates another person's privacy.
Enterprise plans
HIPAA compliance and a BAA are available under an Enterprise agreement. Talk to our team about contractual terms before your organization processes PHI with Arkangel AI.
Where data is processed
The Services are based in the United States and information may be processed there. Arkangel AI is available in the EU under specific conditions with an Enterprise license. If your organization has specific data-protection or data-residency requirements, contact us before deploying.
Security measures
We apply technical and organizational measures to protect the personal information we control against unauthorized access, use, disclosure and accidental loss.

Responsible AI principles

Arkangel AI supports healthcare professionals. It does not provide medical advice, diagnosis or treatment on its own, and our approach follows international guidance on AI for health.

Human validation

Clinicians and reviewers validate every finding. The final clinical, coding or audit decision stays with your team.

Cited sources

Answers link to the studies, guidelines and records they rely on, so professionals can check the evidence themselves.

Clear limits

We state what the product does not do and ask users to verify the original sources before acting on an answer.

Data protection

Use de-identified inputs on self-serve plans, and an Enterprise agreement with HIPAA compliance when PHI is involved.

Guidance we follow

Security and compliance FAQ

Is Arkangel AI HIPAA compliant?

Yes, on Enterprise plans: Arkangel AI offers HIPAA compliance and signs a Business Associate Agreement (BAA); contact us about contractual terms. Inputs on the self-serve Free, Pro and Team plans are not covered by HIPAA, so do not enter protected health information there. Arkangel AI is also ISO 27001:2022 certified, with 70+ security controls monitored via Vanta.

Can ChatGPT be HIPAA compliant?

Consumer ChatGPT is not HIPAA compliant by default, so clinicians should not paste patient identifiers into it. Some enterprise AI offerings support HIPAA through a Business Associate Agreement (BAA). Before any tool handles PHI, confirm its current contract terms, encryption, role-based access and audit trails, and keep identifiers out of consumer chatbots.

Is it safe to use AI for medical diagnosis?

AI can safely support diagnosis when it is validated, protects patient data and a clinician reviews every output; it should not diagnose on its own. WHO and FDA guidance both stress human oversight and transparency. In Arkangel AI, each answer links to its sources and the final clinical decision stays with the healthcare team.

What does the WHO say about AI in health?

WHO guidance on the ethics and governance of AI for health sets six principles: protect autonomy; promote well-being, safety and the public interest; ensure transparency and explainability; foster responsibility and accountability; ensure inclusiveness and equity; and promote responsive, sustainable AI. It calls for human oversight and evaluation in real-world settings.

Is Arkangel AI ISO 27001 certified?

Yes. Arkangel AI is ISO 27001:2022 certified. Its security program includes more than 70 controls covering infrastructure, data privacy and audit procedures, plus penetration testing and continuous monitoring via Vanta. Certification details and policies are available in the Arkangel AI Trust Center at compliance.arkangel.ai.

Planning an Enterprise deployment?

Talk to our team about HIPAA scope, the Enterprise BAA, contractual terms and your security review. Our Trust Center has the documentation your security team will ask for.

Last updated: