Zelavox is built for medical professionals who need to analyze clinical documents quickly — without compromising patient privacy or violating HIPAA.
HIPAA (the Health Insurance Portability and Accountability Act) is a US federal law that protects the privacy and security of patient health information — known as Protected Health Information, or PHI.
PHI includes anything that could identify a patient in connection with their health — names, dates of birth, addresses, medical record numbers, diagnoses, treatment notes, and more.
Important: If you are a healthcare provider, health plan, or healthcare clearinghouse — or a business associate of one — you are required by law to comply with HIPAA whenever you handle PHI. Using a non-compliant tool to process patient documents could result in fines of up to $50,000 per violation.
Zelavox is designed from the ground up to allow medical professionals to use AI document analysis while staying fully HIPAA compliant.
Zelavox operates on a strict zero data retention model. Here is exactly what happens when you upload a medical document:
The result: Zelavox's exposure to your patients' PHI is limited to the seconds it takes to analyze a document. There is no stored PHI to breach, lose, or misuse.
A BAA is a legal contract required by HIPAA whenever a Covered Entity shares PHI with a third-party service provider — called a Business Associate.
When your medical practice uses Zelavox to analyze patient documents, Zelavox becomes your Business Associate. HIPAA requires that we sign a BAA before you upload any PHI.
Do not upload PHI until a BAA is in place. Uploading patient documents to any service without a signed BAA is a HIPAA violation, regardless of how the service handles the data.
Getting a BAA with Zelavox is straightforward. It is available to all users on the Firm plan.
The Firm plan ($299/month, up to 5 users) includes BAA availability and is designed for regulated healthcare environments.
Download our standard BAA template below to review with your compliance officer or attorney before signing.
⬇ Download BAA TemplateDraft template — for attorney review before signing.
Review the BAA with your compliance officer or attorney. Once signed by both parties, you are authorized to upload PHI through Zelavox.
With your BAA in place, you can upload discharge summaries, referral letters, lab reports, and other clinical documents with confidence.
HIPAA compliance is a shared responsibility. Zelavox handles our side — but as the Covered Entity, you remain responsible for:
Only if those documents contain no PHI. If the documents include any patient-identifiable information, you must be on the Firm plan with a signed BAA in place before uploading.
No. Zelavox's zero retention architecture means no document content is ever stored, logged, or retained after analysis is complete. See our full Zero Data Retention Policy for details.
Zelavox uses a leading AI provider that supports zero data retention API options and is willing to execute BAAs for HIPAA-covered use cases. The identity of our AI provider is available upon request — email hello@zelavox.io.
Mental health records carry additional protections under 42 CFR Part 2 and state laws. We recommend consulting your compliance officer or attorney before using Zelavox with substance abuse or mental health records.
Given our zero retention architecture, any breach would be limited to documents actively being processed at the time of the incident — typically a window of under 10 seconds. In the event of any security incident involving PHI, Zelavox will notify affected Covered Entities within the timeframes required by the HIPAA Breach Notification Rule.
Request early access and we'll reach out within 48 hours. Medical practices on the Firm plan can request a BAA immediately upon signup.
Request early access →