Home Features Campaigns Compliance Book a Demo
HIPAA & Washington MHMDA

Compliance Isn't a Feature.
It's the Architecture.

ClinicSpark separates HIPAA-governed clinical data from MHMDA-governed marketing data at the database layer — two zones, one human-operated bridge, zero shortcuts.

Built for clinical practices that want AI-powered workflows without gambling with protected health information.

Two-Zone Data Architecture
BAA-Covered AI, Zero Data Retention
Human-in-the-Loop AI Review

The Two-Zone Architecture

Clinical data and marketing data live under different laws, so they live in different zones — separated by schema at the data layer, not just by policy.

Zone 1 · Clinical

The Clinical Zone

Governed by HIPAA

  • Patient records & demographics
  • Visit notes & treatment protocols
  • Lab documents & AI lab analysis
  • EHR integration data
Every AI call from this zone routes through BAA-covered, zero-data-retention endpoints. Nothing else gets in.

The Bridge

Human-operated.
Consent-driven.
Never automated.

Zone 2 · Marketing

The Marketing Zone

Governed by Washington MHMDA

  • Social content & publishing
  • Prospect data & inquiries
  • Campaign planning & scheduling
  • Email marketing
No PHI ever enters this zone. Marketing tools work with marketing data — full stop.

A Person, Not a Pipeline

Nothing crosses between zones automatically. Every crossing is initiated by a human, backed by documented consent.

Themes, Never Records

Clinical insights cross only as generic themes — "patients ask about thyroid panels" — never as identifiable patient data.

Photos Need Paper

Patient photos require written marketing authorization plus a de-identification review before they can ever appear in Zone 2.

Enforced at the Data Layer — Not Just in the Handbook

The two zones live in separate database schemas. The separation isn't a policy document people are asked to follow; it's a structural boundary the software physically cannot violate.

AI You Can Trust With PHI

Most platforms bolt AI onto health data and hope for the best. ClinicSpark's clinical AI was built inside the compliance boundary from day one.

AWS Bedrock Under a Signed BAA

Clinical AI runs on AWS Bedrock under a signed Business Associate Agreement — the same legal framework that governs your EHR vendor.

Zero Data Retention

AI endpoints retain nothing. Patient data is never stored by the model provider and never used to train models. Ever.

Clinician Review on Every Output

Every AI output is reviewed, editable, and approved by the clinician before it is saved. The AI drafts; the clinician decides.

Human-in-the-Loop Is Mandatory, Not Optional

There is no setting that lets AI output reach a patient record without clinician approval. We didn't build an off switch for judgment.

A Complete BAA Chain

HIPAA compliance breaks at the weakest link. Every vendor that touches PHI in ClinicSpark — hosting, platform engineering, AI, SMS, email — is covered by a Business Associate Agreement.

Audit Trails & Access Control

When an auditor asks "who saw this record and when," the answer should take seconds — not a forensic investigation.

Tamper-Evident Audit Trail

Every meaningful action is recorded in an audit trail designed so that alterations are detectable.

  • Record access, edits, and exports logged
  • Document-access audit logging
  • Consent events captured with timestamps
6-year retention — the HIPAA requirement, built in.

Role-Based Access Control

Access is scoped to clinical roles, so staff see what their job requires — and nothing more.

  • Provider, staff, and admin role tiers
  • Permissions follow the minimum-necessary principle
  • Role changes are themselves audited
The front desk doesn't need lab results to book a visit.

Sessions & Two-Factor Auth

Account security that assumes a busy clinic: shared workstations, interruptions, and shift changes.

  • Automatic session timeouts
  • Two-factor authentication
  • Per-user accountability — no shared logins
A walked-away-from screen isn't an open door.

Your Practice, Your Database

Multi-tenant platforms share tables and trust filters to keep customers apart. ClinicSpark doesn't take that bet.

1
Isolated Database per Practice

Each practice gets its own PostgreSQL database. No shared tables between customers — not filtered, separated.

2
Zones, Separate Schemas

Clinical and marketing data are isolated at the schema level inside each practice's own database.

6 yr
Audit Retention

Tamper-evident audit history retained for six years, matching the HIPAA documentation requirement.

0
PHI Used for Model Training

Zero-data-retention AI endpoints mean patient data is never stored by, or trained into, any model.

All data is encrypted in transit and at rest. If another customer's data can't share a table with yours, an access-control bug can't leak it either.

Washington MHMDA, Handled

Washington's My Health My Data Act treats consumer health data in marketing with near-HIPAA seriousness. ClinicSpark's marketing zone was built for it.

Prospect and marketing data — the people who downloaded your guide, asked about a service, or follow your clinic on social — is consumer health data under MHMDA. The marketing zone manages it with the consent machinery the law expects:

Consent Flows

Consent is collected before consumer health data is used for marketing — built into the prospect intake itself, not appended later.

Withdrawal of Consent

Consumers can withdraw consent, and the withdrawal takes effect across the marketing zone — not just one campaign list.

Record-Keeping

Every consent grant and withdrawal is recorded with a timestamp, so the practice can demonstrate compliance on request.

Opt-Out Management

Opt-outs are managed centrally in the marketing zone, honored across email and campaign channels automatically.

What We Claim — and What We Don't

We tell you exactly where things stand. ClinicSpark is architected for HIPAA and Washington MHMDA compliance, with BAA coverage across every PHI-touching vendor and enforcement built into the data layer. We don't wave certification logos we haven't earned — when third-party attestations are complete, you'll see them here with dates. If you want the details behind any claim on this page, ask us and we'll walk you through the architecture.

Compliance Questions? Talk to Us.

Bring your compliance officer, your privacy counsel, or just your hardest questions. We'll walk you through the Two-Zone Architecture, the BAA chain, and the audit trail — in plain language.

Compliance questions? Talk to us.

Or email us directly: adam@impactme.ai