HIPAA and regulated health data
If you need HIPAA-oriented hosting, a Business Associate Agreement (BAA), or guidance for protected health information (PHI), contact support@genieforge.ai and involve your counsel as needed. GenieForge will discuss the right options with you directly. Until a BAA is in place for your account and the app is approved for PHI under that arrangement, do not put PHI into an app.What to expect once GenieForge engages
After you contact support, GenieForge turns on HIPAA technical safeguards for a specific app and later requests the Business Associate Agreement. The app owner accepts the BAA in App Settings or Document Center. When HIPAA mode is active:- Additional technical safeguards apply (restricted AI providers, shortened sessions, and related controls). Portal sessions last 30 minutes of activity, with a 12-hour maximum before sign-in is required again. Builders and admins who must use MFA (including anyone with access to a HIPAA app) are signed out after 30 minutes idle and 12 hours from sign-in. An open tab that only refreshes in the background (inbox counts, Executions, chat polling) does not keep a builder session alive. New builder passwords must be at least 12 characters and include letters and digits.
- Connected accounts (OAuth integrations such as Slack, Google, GitHub, and similar) are not available. Those providers are not covered by a Business Associate Agreement.
- App email does not put clinical content in Gmail or Outlook. People get a sign-in link and read the message in Notifications (or Inbox, for builders).
- First-party Usage still records page and job counts (not chat text or form values) with a shorter retention window, so you can see what people actually used.
- Portal end users must use an authenticator app after their password. First sign-in walks them through enrollment and one-time recovery codes. If someone loses their authenticator, an app admin can reset MFA under End-Users so they can enroll again.
- You must publish an end-user privacy notice under App Settings → Privacy (your Notice of Privacy Practices). End users must acknowledge the latest version before they can use the portal.
- Custom domains for HIPAA apps are arranged with GenieForge, not from the usual Project Settings self-serve flow.
- After the app owner accepts the BAA, App Settings → Privacy shows HIPAA as enabled under that BAA. GenieForge does not claim that your overall practice or app is “HIPAA certified.” Your configuration, notices, and counsel review still matter.
- After the BAA is accepted, the app owner and admins can still export a backup from App Settings. That download is recorded in Access log. GenieForge staff cannot download the blueprint. The file omits test suite source and decision write-ups.
- Accepting the BAA asks the owner to review who currently has access (collaborators, organization members, and pending invites) and confirm the list before HIPAA is enabled. If that list changes after you open it, you will need to review it again. Remove app access from App Settings → Access first. Organization members and pending org invites are removed from the organization, not from that Access list.
- Workspace billing (customers paying you through the portal) stays available. Stripe is used only to take payment, not as a business associate. GenieForge does not send customer names, plan names or descriptions, or health information to Stripe. The app owner must acknowledge this payment-only mode in App Settings → Billing before turning billing on. Do not put health information in plan names or anything else that reaches the payment processor. The portal still shows your real plan names to workspace owners.

