For Enterprise customers only: Learn about Superhuman Docs' HIPAA compliance, including requirements, product use considerations, restrictions, & more.
Superhuman’s security and privacy strategy is built on well-established principles that guide how we secure Docs and keep your data safe. For customers subject to the requirements of the Health Insurance Portability and Accountability Act (“HIPAA”) who intend to upload, transmit, and communicate Protected Health Information (“PHI”), Superhuman can assist with their HIPAA compliance efforts through our Docs Enterprise plan.
Requirements for enabling HIPAA compliance
Enterprise-level Superhuman Docs plan: HIPAA compliance is only offered to customers on the Docs Enterprise plan.
Signed Business Associates Agreement (BAA): Superhuman BAA governs the handling and protection of Protected Health Information.
Configurations and product use considerations: See the table below.
📣 If you're interested in upgrading to an Enterprise plan or would like to discuss any of the above requirements with our team, please contact us here.
Configuration and product use considerations
The following table provides Docs features and configurations to support your HIPAA compliance obligations.
HIPAA Standards |
How Superhuman Docs Supports Compliance |
|
Access Control Implement technical policies and procedures for electronic information systems that maintain electronic protected health information to allow access only to authorized persons or software programs. |
Enable SAML SSO: Superhuman Docs supports open standard SAML 2.0 and can work with your Identity Provider (IdP) of choice. For organizations managing multiple workspaces, Docs' SAML implementation supports provisioning access to specified workspaces based on IdP user attributes. Packs control: All integrations and Packs can be configured to be disallowed or require admin approval prior to installation. The Packs platform also provides advanced configurations for admins to control data schemas/type allowed in Packs. Personal access tokens: Personal access tokens can be disabled at the organization level by Superhuman Support. |
|
Unique User Identification Assign a unique name and/or number for identifying and tracking user identity. |
SAML/SCIM: In addition to SAML login, Docs has a SCIM API allowing admins to provision, manage, and deprovision members directly from their IdPs. |
|
Automatic Logoff Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity. |
Session period: The default session period is 30 days. Customers who require a different session period may reach out to support to set a custom session timer. |
|
Audit Controls Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information. |
Audit log: Superhuman Docs has an in-product Audit log dashboard that lists the audit events for your organization. Admin API: Docs offers an Admin API that can be used to integrate with your preferred SIEM (Security Information and Event Management) system. Superhuman Docs retains these audit events for a year. Customers may use the Admin API to store logs in their preferred SIEMs for longer durations. |
|
Integrity Controls Implement policies and procedures to protect electronic protected health information from improper alteration or destruction. Implement electronic mechanisms to corroborate that electronic protected health information has not been altered or destroyed in an unauthorized manner. Implement security measures to ensure that electronically transmitted electronic protected health information is not improperly modified without detection until disposed of. |
Audit Log: Audit logs provide an immutable record of events within an organization. Admin API: The Admin API allows users to integrate with external services for customers who require custom retention and/or backup of their logs. Sharing restrictions: Admins may set sharing restrictions and can prevent external sharing entirely. This includes the ability to enable/disable publishing of docs. Folder permissions: All folders are set to private by default upon creation. Legal holds: Available as a paid add-on. This feature allows admins to place legal holds on users and preserve their docs for a specific amount of time. Workspaces: Admins may restrict the creation of new workspaces by their users. Data Export: Admins may configure the ability for users to export their documents. Admins may export their organization’s data and any time. |
|
Transmission Security Implement a mechanism to encrypt electronic protected health information whenever deemed appropriate. Implement a mechanism to encrypt and decrypt electronic protected health information. |
Encryption: Superhuman Docs uses the AWS Key Management Service (KMS) to create, maintain, and rotate encryption keys. Data transmitted between customers and Docs' service is protected using TLSv1.2 or higher. Data at rest is encrypted using AES-256 symmetric encryption algorithm |
|
Data Retention and Disposal Implement policies and procedures to address the final disposition of electronic protected health information, and/or the hardware or electronic media on which it is stored. |
Data retention and disposal: Deleted documents are kept in our primary storage systems for 7 days to allow for accidental deletions to be reverted. After this 7-day period, they are permanently removed from our primary storage systems. Deleted data will still be retained in backups for 35 days. Once this 35-day retention period is over, the customer data will no longer be present in the backups. |
Limitations and restrictions
- Users - Docs is not an EHR (Electronic Health Record) and is not designed to be the system of record for health information. Customers may not use Docs to communicate with patients, patient family members, plan members, or their employers.
- Packs - The Pack Gallery provides access to third-party integrations for tools that work with Docs’ services. These services (including two-way sync) are not covered by the Superhuman BAA. It is up to you, the customer, to 1) determine whether a BAA with such third-party tool is required, and 2) execute such an agreement directly with the third party.
- Connectors - Docs can be used as a connector or app in certain third-party products. Using Docs integrated through third-party products is not covered by Superhuman’s BAA.
-
PHI Prohibited Fields - Users may not include PHI in any of the following:
- Organization names
- URL domains
- Support Services - When submitting support requests, users must not include any PHI in the message contents or in any file uploads, including screenshots, documents, etc. This includes all support methods (in-product widget, email, phone, chat, etc.).
-
Docs AI Features - While our team works to bring these features under our BAA in the future, for the time being, the following Docs AI features will be unavailable for customers subject to our BAA
-
Web Search:
- Impact: Removing this functionality means the agent cannot search the web for the latest data and must rely on its training, which may lead to outdated results.
-
Prompt Caching & Removal of Extended Cache TTL:
- Impact: Removing this functionality will likely lead to higher costs due to increased token usage and slower speeds because requests will need to be completed in their entirety each time rather than relying on cached data.
-
Tool Streaming:
- Impact: Removing this functionality will have minimal impact, resulting in slightly limited feedback from the agent for certain types of progress updates.
-
Vision:
- Impact: Removing this functionality removes the ability to upload images and PDFs to the AI chat. Docs MCP can be used to import image data using the integration(s) you use with the Docs MCP, subject to the MCP note below.
-
Beta Headers (
extended-cache-ttlandfine-grained-tool-streaming)
-
Web Search:
-
MCP - The Superhuman Docs MCP itself is HIPAA compliant. However, you are responsible for ensuring any tool or service you connect to the Docs MCP is HIPAA compliant.
Privacy, certifications, and compliance
It is important to note that there is no certification recognized by the US HHS for HIPAA compliance and that complying with HIPAA is a shared responsibility between the customer and Superhuman.
Please review our terms, privacy policy, and DPA for more information about our privacy practices.