AI Disclaimer: Kevin! is an AI assistant for documentation support only. It does not provide medical advice, diagnosis, or treatment. All outputs require review by licensed healthcare professionals. Learn more
Back to home
Trust & Security

Your Data. Our Responsibility.

Kevin! is built from the ground up for healthcare. We implement the security and compliance safeguards your patients and practice deserve — because trust isn't optional when lives are involved.

Security at a Glance

Encrypted Everywhere

TLS 1.2+ in transit, AES-256 at rest. Your data is encrypted at every stage.

HIPAA Compliant

Full administrative, physical, and technical safeguards per HIPAA Security Rule.

SOC 2 Infrastructure

Hosted on Google Cloud Platform — SOC 2 Type II certified data centers.

Continuous Monitoring

Real-time intrusion detection, vulnerability scanning, and audit logging.

Infrastructure & Encryption

Technical Safeguards

  • TLS 1.2+ encryption for all data in transit
  • AES-256 encryption for all data at rest
  • Role-based access controls (RBAC)
  • Multi-factor authentication (MFA)
  • Regular vulnerability scanning & pen testing
  • Automated security patching
  • Secure software development lifecycle

Administrative Safeguards

  • Designated Privacy & Security Officers
  • Workforce HIPAA training
  • Documented security policies & procedures
  • Regular risk assessments & audits
  • Background checks for data-access roles
  • Vendor security assessments
  • Incident response plan & procedures

Google Cloud Platform — All data is hosted on GCP infrastructure with SOC 2 Type II certification, ISO 27001 compliance, and a signed HIPAA Business Associate Agreement. View Google Cloud compliance →

HIPAA Compliance

When healthcare providers use Kevin! to process Protected Health Information (PHI), Rushin InTegrations acts as a Business Associate under HIPAA. We implement the full spectrum of safeguards required by the HIPAA Security Rule and maintain strict compliance with the Privacy Rule and Breach Notification Rule.

BAAs Available

We provide Business Associate Agreements for all healthcare customers before any PHI is transmitted.

Access Controls

Role-based access, MFA, and minimum necessary standard — we access only the PHI needed to deliver services.

Workforce Training

All team members receive mandatory HIPAA privacy and security training with annual refreshers.

Breach Notification

Formal incident response plan with notification to covered entities within 60 days of discovery.

HIPAA Security Rule
HIPAA Privacy Rule
HITECH Act
Breach Notification Rule

AI & Your Data

🚫 We do NOT use your data to train AI models. Period.

Your clinical inputs and PHI are used solely to provide Kevin!'s services to you. Any model improvements use fully de-identified or synthetic data.

AI Processing

All AI inference runs through Google Vertex AI, covered by our Google Cloud BAA. No PHI is sent to any third-party AI provider without a signed Business Associate Agreement.

Voice Dictation

Audio is processed in real-time and deleted immediately after transcription. Raw audio is never retained unless you explicitly opt in. Speech-to-text is powered by AssemblyAI under a signed BAA.

Subprocessor Obligations

All subprocessors are contractually bound to process data only as instructed, never use your data for their own purposes, maintain equivalent security standards, and enter into BAAs where required.

Incident Response

We maintain a formal Incident Response Plan that defines how we detect, contain, investigate, and resolve security incidents. In the event of a breach of unsecured PHI:

Rapid Detection

Continuous monitoring and automated alerting to identify incidents in real-time.

Immediate Containment

Affected systems are isolated within hours. Evidence is preserved for investigation.

Timely Notification

Covered entities notified within 60 days of discovery, with full incident details.

Every incident is documented, reviewed, and used to strengthen our security posture. Post-incident reviews are conducted within 14 days of closure.