Glitter AI provides a HIPAA compliant environment for creating and sharing process documentation, and helps you meet your own compliance obligations when your guides touch Protected Health Information (PHI). This page explains how that works, what we take care of, and what stays your responsibility.
Plain-English Summary
Heads up: This is a summary for your convenience. Your Business Associate Agreement and our Subscription Terms are what actually govern our agreement.
- We sign a BAA with you: HIPAA compliance on Glitter starts with a Business Associate Agreement between your organization and Glitter AI, Inc. It's available as an add-on - see pricing.
- HIPAA-eligible infrastructure: Once HIPAA is enabled for your organization, all AI processing of your recordings and guides runs on infrastructure covered by BAAs we hold with our vendors.
- Enforced, not promised: The platform locks public sharing off for your entire organization, restricts embedding to access-controlled embeds, and keeps guides visible to signed-in members only. These controls can't be switched off by your users.
- Your data is never used for AI training: Not by us, not by our providers. This predates HIPAA and applies to every customer.
- SOC 2 Type II underneath: HIPAA controls sit on top of the same independently audited security program that covers all of Glitter. Reports at trust.glitter.io.
What HIPAA is
The Health Insurance Portability and Accountability Act (HIPAA) is a US federal law that protects individuals' health information. It sets privacy and security standards that must be followed by everyone who handles PHI - health plans, providers, clearinghouses, and the vendors that serve them. If your team documents workflows inside an EHR, a billing system, a patient intake tool, or anything else where PHI can appear on screen or in narration, HIPAA applies to that documentation too.
How Glitter fits in
Under HIPAA, organizations that handle PHI directly are covered entities, and vendors that process PHI on their behalf are business associates. When you use Glitter to document PHI-touching workflows, you're the covered entity and Glitter is your business associate. That relationship is formalized in a written Business Associate Agreement (BAA) - and we hold BAAs with our own vendors that could access PHI, so the chain of accountability doesn't break at our door.
When we enable HIPAA for your organization, the platform itself changes behavior:
- All AI processing of your recordings and guides - transcription, step extraction, and guide generation - runs on HIPAA-eligible infrastructure covered by our vendor BAAs
- Public sharing is locked off organization-wide - existing public guides are made private, and new guides can't be made public
- Embedding is restricted - only token-protected secure embeds (or no embeds at all), never open iframes
- Guides stay inside your organization - visible to signed-in members only
These aren't policies your admins have to remember to configure. They're enforced by the platform and can't be weakened by individual users. We'd rather compliance be something the product does than something a checklist asks you to do.
Your responsibilities
As the covered entity, you agree to a few things when you store PHI in Glitter:
- Comply with the HIPAA Rules. The Privacy Rule, Security Rule, and Breach Notification Rule apply to your organization directly.
- Sign a BAA with us before storing PHI. Recording PHI into Glitter without a BAA in place is a compliance gap on both sides - reach out and we'll get it signed first.
- Run your own compliance program. Access control inside your organization, workforce training, and risk assessments remain yours. Glitter gives you the enforced-private environment; how your people use it is governed by your policies.
Our responsibilities
- Direct liability. As a business associate we're directly liable under HIPAA for safeguarding ePHI and for reporting breaches to you.
- Compliance with the BAA. We implement the administrative, physical, and technical safeguards the agreement requires - encryption in transit and at rest, access controls, monitoring, and the platform enforcement described above.
- Vendor management. Every vendor that could access ePHI operates under a BAA with us. Our full vendor list is public at Sub-Processors.
Staying compliant
Compliance is a continuous process, not a point-in-time audit. Glitter's security controls are independently audited every year (SOC 2 Type II), and the HIPAA enforcement controls are part of the platform itself - they don't drift between audits because they can't be turned off between audits. You can review our audit reports, security documentation, and certifications at our Trust Center.
Frequently asked questions
Is there such a thing as "HIPAA certified"?
No. Unlike SOC 2, there is no official certifying body for HIPAA. Anyone claiming a HIPAA certification is describing a self-assessment or third-party review, not a government certification. What matters is a signed BAA and demonstrable safeguards - which is exactly what we provide.
What's the difference between SOC 2 and HIPAA?
Both are frameworks for protecting sensitive data, and they share many controls. SOC 2 is industry-agnostic and independently audited; HIPAA is a US federal regulation specific to health information. Glitter applies the same SOC 2 controls to every environment, with the additional HIPAA enforcement applied to organizations under a BAA.
Which plan do I need?
The BAA (HIPAA) is available as a paid add-on - see pricing. Because a BAA is a signed legal agreement, setup starts with a conversation: reach out via the chat bubble or security@glitter.io.
What changes for my team when HIPAA is enabled?
Day-to-day guide creation works exactly the same - record, narrate, get a polished guide. The changes are in where processing happens and how sharing works: everything stays private to your organization, and the sharing surfaces that could expose PHI publicly are removed rather than merely discouraged.
Can I evaluate Glitter before signing a BAA?
Absolutely - just don't record PHI during the evaluation. Use test data or PHI-free workflows until the BAA is in place and HIPAA is enabled for your organization.
Resources
- HIPAA on Glitter AI - product overview
- HIPAA (HHS.gov)
- HIPAA Privacy Rule
- HIPAA Security Rule
- Breach Notification Rule
- Glitter Trust Center - SOC 2 reports and security documentation
- Sub-Processors - every vendor that may process your data
- Data Processing Addendum
- AI Security & Privacy
Questions your compliance team needs answered? Email security@glitter.io - we'll get back to you promptly, and we're happy to walk your auditor through our controls.