How Sefton handles PHI
Trust & Security
How Sefton protects your data. Operated by Sefton Health, Inc.

Our role under HIPAA
Sefton is built to support HIPAA compliance. For Protected Health Information (PHI), Sefton Health, Inc. acts as a Business Associate of your practice (the covered entity), under a signed Business Associate Agreement. Your practice controls patient PHI; we process it only to provide the service.
Safeguards
- Encryption in transit and at rest
- Access controls and least-privilege; tenant isolation
- Multi-factor and passkey (WebAuthn) authentication options
- PHI-aware audit logging and incident response
- Secrets management and security headers / origin controls
Our commitment on AI and your data
We do not sell your information, and we do not use PHI to train, fine-tune, or improve any AI or machine-learning model — first-party or third-party, general-purpose or special-purpose — except solely to deliver the feature you asked for to your own practice. This is a contractual, non-waivable commitment in our Business Associate Agreement, not just a policy statement. AI features provide administrative support only; your clinician reviews and is responsible for every note and code.
Sub-processors (PHI-bearing)
These vendors process PHI to provide the service and operate under signed Business Associate Agreements:
| Sub-processor | Scope | BAA |
|---|---|---|
| Cloud infrastructure provider | HIPAA-eligible hosting, PHI runtime, and AI/media processing when enabled | Signed |
| Claim.MD | Clearinghouse + ERA / remittance | Signed |
Vendors kept out of PHI scope
Payment, push-notification, sign-in identity, and source-control vendors are deliberately kept out of PHI scope — their payloads never carry patient information. A full vendor inventory is available to customers under NDA on request.
Change notice
We will update this page and provide notice by reasonable means before adding a new PHI-bearing sub-processor.
Certifications
We do not currently hold third-party security certifications, and we do not overstate our certification status. Available security documentation can be provided under NDA to customers on request.
Reporting a concern
Security questions or reports: privacy@sefton.health. If you believe your privacy rights have been violated, you may also contact your provider (the covered entity) or the U.S. Department of Health and Human Services, Office for Civil Rights.