Document PHI workflows without the compliance headache

Sign a BAA with Glitter AI and every recording and guide is processed on HIPAA-eligible infrastructure - with privacy controls the platform enforces for your entire organization, automatically.

Built for teams whose screens can't leak

Healthcare operations run on software - and documenting that software means recording screens where PHI lives.

Your workflows live inside PHI

EHR walkthroughs, patient intake, billing systems, claims processing - the screens your team needs documented are the same screens HIPAA protects.

Screen recording tools are a liability

Most documentation tools ship recordings to whatever AI vendor is cheapest, with public share links one click away. For PHI, that is an incident waiting to be reported.

Training still has to happen

Compliance can't mean going back to screenshots pasted into Word. New hires still need clear, current guides for the systems they will use on day one.

Policies drift, people forget

A sharing policy in a handbook is only as strong as the busiest person on your team. Real compliance needs controls the product enforces for you.

How HIPAA on Glitter works

Three steps - and only the first one needs a signature.

Step 1

Sign the BAA

A Business Associate Agreement between your organization and Glitter AI, Inc. - the legal foundation HIPAA requires before PHI touches any vendor.

Step 2

We enable HIPAA for your org

One switch on our side moves all AI processing of your recordings and guides to HIPAA-eligible infrastructure covered by our vendor BAAs.

Step 3

The platform enforces the rest

Privacy controls apply to every member and every guide, automatically. Nothing to configure, nothing to remember, nothing to audit for drift.

Enforced for your entire organization

When HIPAA is on, these aren't settings - they're guarantees. No admin checkbox can weaken them.

  • Public link sharing Locked off, organization-wide
  • Embedding Secure, token-protected embeds only
  • Guide access Signed-in members of your organization
  • AI processing HIPAA-eligible infrastructure under vendor BAAs

Compliance is shared - here's the split

HIPAA names two parties: the covered entity (you) and the business associate (us). Each side has a job.

What stays with you

  • Your HIPAA compliance program, training, and risk assessments
  • Who in your organization can create and view guides
  • Signing the BAA before recording PHI
  • Following the Privacy, Security, and Breach Notification Rules

What Glitter takes care of

  • HIPAA-eligible AI processing under BAAs with our vendors
  • Platform-enforced private-only sharing for your organization
  • Encryption in transit and at rest, access controls, and monitoring
  • Breach notification and direct liability as your business associate
Signed BAA SOC 2 Type II AES-256 encryption Never used for AI training On-device redaction

HIPAA questions, answered

Does Glitter AI sign a BAA?

Yes. HIPAA compliance on Glitter starts with a Business Associate Agreement between your organization and Glitter AI, Inc. It is available as a paid add-on - see pricing. We also hold BAAs with every vendor of ours that could access PHI, so the chain of accountability does not break at our door.

What actually changes when HIPAA is enabled for my organization?

All AI processing of your recordings and guides moves to HIPAA-eligible infrastructure, public sharing is locked off for your whole organization, and embedding is restricted to token-protected secure embeds. These controls are enforced by the platform - individual users cannot weaken them.

Is my content used to train AI models?

Never. We never have, and never will, use your content to train AI models, nor allow any third party to do so. This commitment applies to every customer and is legally binding in our Subscription Terms.

Is Glitter "HIPAA certified"?

No one is - there is no official HIPAA certifying body. What matters is a signed BAA and demonstrable safeguards. Glitter is SOC 2 Type II certified, our security controls are independently audited every year, and the HIPAA enforcement is built into the platform itself. Details on our HIPAA compliance page.

Can my team still blur sensitive information?

Yes - and for maximum privacy you can do it on-device. The desktop app can blur sensitive data locally before anything leaves your machine, and cloud redaction wipes every version of the blurred region from our servers.

How do we get started?

Reach out via the chat bubble or email security@glitter.io. We will sign the BAA, enable HIPAA for your organization, and your team keeps documenting exactly as before - just inside an environment built for PHI.

Ready to document safely?

Tell us about your team and we'll take it from there - BAA first, then HIPAA is on for your whole organization. Your compliance team is welcome on the call.