You control who sees your data
Providers access your Health 360 only when you tap Share with Doctor or approve a verification request. Revoke anytime in Settings.
You hold the keys to your Health 360. Your entire health profile, vitals, and documents are housed in a secure storage vault built on HIPAA-compliant AWS infrastructure, protected with AES-256 encryption, and nothing is shared without your explicit consent.
Providers access your Health 360 only when you tap Share with Doctor or approve a verification request. Revoke anytime in Settings.
Your health information is not sold or shared with advertisers. We use data only to deliver ZivoHealth services to you and your consented care team.
Labs, prescriptions, vitals, and EMR uploads live in an encrypted secure vault on AWS S3 — AES-256 at rest with managed keys and TLS in transit. “Secure vault” is our name for that encrypted S3 storage; see our Privacy Policy.
ZivoHealth runs on Amazon Web Services using HIPAA-compliant services under a Business Associate Agreement — the same cloud standard used by leading healthcare organizations.
Compute, storage, and databases run on HIPAA-compliant AWS services — with encryption, access controls, and monitoring at every layer.
ZivoHealth maintains a Business Associate Agreement with AWS covering all electronic protected health information stored and processed in our cloud environment.
When Zivo AI uses cloud inference, we work only with vendors under a BAA or equivalent healthcare addendum. Your PHI is sent over encrypted channels solely to return results to you — never to train public or open-source models.
Uploaded documents and health files are stored in an encrypted vault on Amazon S3 within our HIPAA-compliant AWS account — server-side encryption and managed keys, covered by our AWS BAA.
Data residency, subprocessors, and how we handle cross-border transfers are documented in our Privacy Policy.
Your data is encrypted the moment it leaves your device and remains encrypted in our secure vaults.
Every sync, upload, and video visit travels over encrypted HTTPS connections.
Health records, labs, and vitals are encrypted before they are written to storage — including our secure vault on AWS S3. Keys are managed separately from application data.
ZivoHealth is designed so you grant access scope by scope. There is no “share everything by default.”
Zivo AI operates within an isolated, secure environment on our infrastructure. Your personal health data is never sold, never shared with third-party advertisers, and never used to train public or open-source AI models. When AI features need cloud inference, PHI is sent only over encrypted channels to serve your request — not to build a global training corpus.
We use only AI service providers under a Business Associate Agreement or equivalent healthcare addendum for paths that may process PHI — including OpenAI, Anthropic, and Amazon Web Services (Amazon Bedrock). Under those agreements and our configured settings, vendors process health data solely to deliver AI-assisted features you choose to use; they do not train public foundation models on your identifiable records.
Healthcare providers and clinic administrators need more than a consumer privacy blurb. Here is how ZivoHealth handles PHI, AI, and accountability.
ZivoHealth signs Business Associate Agreements with covered entities and enterprise partners where required. Contact contactus@zivohealth.ai for enterprise BAA requests.
Infrastructure: Our AWS BAA covers HIPAA-compliant cloud infrastructure — compute, storage, and databases that hold your Health 360.
AI service providers: When generative AI features may process PHI, we maintain healthcare data processing agreements (including BAA or healthcare addendum coverage, where applicable) with the vendors we use — currently OpenAI, Anthropic, and Amazon Web Services (Amazon Bedrock). PHI is sent server-to-server over encrypted channels only to return results for features you enable; it is not used to train public foundation models or for advertising. See Privacy Policy — Third-party generative AI.
Clinical partners: Provider-facing DPAs cover marketplace clinical workflows.
ZivoHealth is built on HIPAA-compliant AWS services under a Business Associate Agreement and applies healthcare-grade encryption and access controls. See our Privacy Policy for full details.
Access is restricted by role, encrypted storage, and audit logging. We do not use your health data for advertising.
No. Your identifiable health data is not used to train public or open-source models. Cloud AI vendors we use (OpenAI, Anthropic, AWS Bedrock) are under healthcare data processing agreements. See Our AI Privacy Pledge.
Use in-app sharing and consent controls — providers only see data you approve for each verification or visit.
Yes — with covered entities and enterprise partners where applicable. Contact contactus@zivohealth.ai.
Consent events, access requests, sync activity, and clinical workspace actions are logged for security and compliance review.
AI assists clinical workflows you control; inference runs in Zivo’s secure environment with vendors under BAA or healthcare addenda (OpenAI, Anthropic, AWS Bedrock) — not for public model training.
Download the app or join as a provider on the same secure platform.