Trust & Security

Complete Privacy for Your Personal Health Data.

You hold the keys to your Health 360. Your entire health profile, vitals, and documents are housed in a secure storage vault built on HIPAA-compliant AWS infrastructure, protected with AES-256 encryption, and nothing is shared without your explicit consent.

You're in control — from every sync to every share

You control who sees your data

Providers access your Health 360 only when you tap Share with Doctor or approve a verification request. Revoke anytime in Settings.

We never sell your data

Your health information is not sold or shared with advertisers. We use data only to deliver ZivoHealth services to you and your consented care team.

Encrypted secure vault

Labs, prescriptions, vitals, and EMR uploads live in an encrypted secure vault on AWS S3 — AES-256 at rest with managed keys and TLS in transit. “Secure vault” is our name for that encrypted S3 storage; see our Privacy Policy.

Built on HIPAA-compliant AWS architecture

ZivoHealth runs on Amazon Web Services using HIPAA-compliant services under a Business Associate Agreement — the same cloud standard used by leading healthcare organizations.

Diagram: ZivoHealth app on your device connects through TLS 1.3 encryption to HIPAA-compliant AWS infrastructure with application layer, AES-256 encrypted stores, and isolated AI workloads

Secure infrastructure

Compute, storage, and databases run on HIPAA-compliant AWS services — with encryption, access controls, and monitoring at every layer.

BAA with AWS

ZivoHealth maintains a Business Associate Agreement with AWS covering all electronic protected health information stored and processed in our cloud environment.

BAA for AI data sharing

When Zivo AI uses cloud inference, we work only with vendors under a BAA or equivalent healthcare addendum. Your PHI is sent over encrypted channels solely to return results to you — never to train public or open-source models.

Secure vault on AWS S3

Uploaded documents and health files are stored in an encrypted vault on Amazon S3 within our HIPAA-compliant AWS account — server-side encryption and managed keys, covered by our AWS BAA.

Regional safeguards

Data residency, subprocessors, and how we handle cross-border transfers are documented in our Privacy Policy.

Encryption from your device to our vault

Your data is encrypted the moment it leaves your device and remains encrypted in our secure vaults.

In transit — TLS 1.3

Every sync, upload, and video visit travels over encrypted HTTPS connections.

At rest — AES-256

Health records, labs, and vitals are encrypted before they are written to storage — including our secure vault on AWS S3. Keys are managed separately from application data.

Our AI Privacy Pledge

Your health data stays yours — even with Zivo AI

Zivo AI operates within an isolated, secure environment on our infrastructure. Your personal health data is never sold, never shared with third-party advertisers, and never used to train public or open-source AI models. When AI features need cloud inference, PHI is sent only over encrypted channels to serve your request — not to build a global training corpus.

We use only AI service providers under a Business Associate Agreement or equivalent healthcare addendum for paths that may process PHI — including OpenAI, Anthropic, and Amazon Web Services (Amazon Bedrock). Under those agreements and our configured settings, vendors process health data solely to deliver AI-assisted features you choose to use; they do not train public foundation models on your identifiable records.

  • Sandboxed AI workloads on Zivo-controlled AWS
  • BAAs with OpenAI, Anthropic, and AWS Bedrock for cloud AI inference
  • No training of public LLMs on your identifiable health records
  • AI supports — your licensed provider makes clinical decisions

Data governance for clinical partners

Healthcare providers and clinic administrators need more than a consumer privacy blurb. Here is how ZivoHealth handles PHI, AI, and accountability.

Business Associate Agreements

ZivoHealth signs Business Associate Agreements with covered entities and enterprise partners where required. Contact contactus@zivohealth.ai for enterprise BAA requests.

Infrastructure: Our AWS BAA covers HIPAA-compliant cloud infrastructure — compute, storage, and databases that hold your Health 360.

AI service providers: When generative AI features may process PHI, we maintain healthcare data processing agreements (including BAA or healthcare addendum coverage, where applicable) with the vendors we use — currently OpenAI, Anthropic, and Amazon Web Services (Amazon Bedrock). PHI is sent server-to-server over encrypted channels only to return results for features you enable; it is not used to train public foundation models or for advertising. See Privacy Policy — Third-party generative AI.

Clinical partners: Provider-facing DPAs cover marketplace clinical workflows.

De-identification for AI
Where AI can run on reduced identifiers, Zivo applies de-identification and data-minimization practices before inference — limiting exposure of direct identifiers in model pipelines. PHI used for your patient’s care stays tied to consent and clinical purpose.
Immutable audit trails
Access requests, consent changes, data sync events, and provider interactions are logged for security review and compliance workflows — supporting accountability across the patient–provider bridge.
India DPDP Act alignment
For Indian users, clinical providers act as Data Fiduciaries for treatment records; ZivoHealth acts as Data Processor under the Data Processing Addendum.

Frequently asked questions

Is ZivoHealth HIPAA compliant?

ZivoHealth is built on HIPAA-compliant AWS services under a Business Associate Agreement and applies healthcare-grade encryption and access controls. See our Privacy Policy for full details.

Can ZivoHealth employees read my health records?

Access is restricted by role, encrypted storage, and audit logging. We do not use your health data for advertising.

Is my data used to train AI?

No. Your identifiable health data is not used to train public or open-source models. Cloud AI vendors we use (OpenAI, Anthropic, AWS Bedrock) are under healthcare data processing agreements. See Our AI Privacy Pledge.

How do I share data with my doctor?

Use in-app sharing and consent controls — providers only see data you approve for each verification or visit.

Ready to trust your Health 360 with Zivo?

Download the app or join as a provider on the same secure platform.