Skip to main content
Agnodice

Security and compliance, stated plainly

Agnodice is pre-launch. It handles no patient data, has no customers, and holds no independent security attestation. This page says what exists today, how we intend to build, and what we commit to before any patient data is handled. Where something is not yet true, this page says so plainly rather than implying otherwise.

Where we are today

Customers
None
Patient data handled
None
Business associate agreements signed
None
Independent security assessment or attestation
None
Security and privacy officials
To be named before launch

How we intend to build it

  • Least privilege

    Each agent and service is designed to hold only the access its task needs.

  • Tenant isolation in the database

    Each practice's data is designed to be separated by rules enforced in the database, not only in application code.

  • Fail closed

    When a rule cannot be checked, the action is designed to stop rather than proceed.

  • Minimum necessary data

    A model is designed to receive only the data a task needs.

  • Agreements and US processing

    Patient data is designed to go only to providers under signed agreements, with processing in US regions.

  • A complete audit trail

    Every automated decision is designed to be recorded together with what was used to make it.

Commitments before we handle patient data

  1. Sign a business associate agreement with each practice.
  2. Complete and document a security risk analysis.
  3. Commission an independent security assessment.
  4. Name the officials responsible for security and privacy.

What is not done yet

  • No security attestation or certification has been obtained.
  • No business associate agreement has been signed.
  • No patient data has been handled, and none is accepted through this site.
  • The design described on this site has not been independently reviewed.

Raise a concern

If anything on this site is unclear or wrong, tell us through the contact form.