Security & Compliance

HIPAA-Aware Design

Continuum is a mentorship and career-development platform — not an electronic health record system. We're built so that Protected Health Information (PHI) doesn't enter the platform in the first place. Here's exactly what that means, what we promise, and where we draw the line.

The honest position: Continuum Health AI is not "HIPAA-certified." There is no such certification under U.S. law — HIPAA compliance is a posture, not a credential. What we are is HIPAA-aware: designed from the start to keep PHI out, with security controls and contractual safeguards appropriate for a non-PHI mentorship platform. If your use case requires us to handle PHI, we can sign a Business Associate Agreement (BAA) with the right Supabase tier configured — see BAA Request.

01 What we don't ask for, store, or process

The single most reliable HIPAA strategy is simply not handling PHI. Our product design enforces this:

The Terms of Service §2 prohibits posting PHI through the platform. Mentorship conversations are between healthcare professionals about their own careers, not their patients.

02 What we do collect

Our data minimization approach: collect only what's needed to make a good match and run the service. See our Privacy Policy for the full inventory. The high-level categories:

03 Acceptable use — for users

✓ Yes, this is fine

  • "I'm working on a research project on hip-fracture outcomes."
  • "I had a tough M&M last week — how do you handle bad outcomes emotionally?"
  • "What did you do for your sub-I rotation in cardiology?"
  • "My program director said X — is that a red flag?"

✗ Don't put this on the platform

  • Patient names, MRNs, DOBs, or any other identifiers
  • Specific case details that could re-identify a real patient
  • Photos containing patient information (badges, charts, screens)
  • Lab values, imaging, or notes copied from an EHR

If you're uncertain whether a clinical question crosses the line, abstract it. "I had a young patient with severe complications" is fine; "32-year-old [name] at [hospital] with..." is not.

04 Security posture

Even though we don't store PHI, healthcare professionals trust us with sensitive career and identity data. Our security controls reflect that:

05 When a BAA is appropriate (and when it isn't)

A Business Associate Agreement under HIPAA is required when a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity. By design, Continuum does none of those things in standard use. Most institutional pilots do not need a BAA — the platform sits next to clinical work, not inside it.

When a BAA might still be requested:

In those cases, BAA execution and HIPAA-compliant infrastructure enablement (Supabase Team + HIPAA add-on) are part of the institutional onboarding process — not capabilities enabled in default production today. Reach out via BAA Request with your institutional details and we'll acknowledge within five business days with a current-status update.

06 Breach notification

If we become aware of a security incident affecting your account data, we will notify you by email within 72 hours of confirmation, with as much detail as we have at that time. This commitment applies to all users regardless of BAA status, and is more aggressive than HIPAA's strict 60-day timeline.

Suspected security issues? Email [email protected]. We acknowledge reports within one business day.

07 Limitations and honest caveats

08 Contact

Institutional security review, BAA request, or compliance question?