ClinicSpark separates HIPAA-governed clinical data from MHMDA-governed marketing data at the database layer — two zones, one human-operated bridge, zero shortcuts.
Built for clinical practices that want AI-powered workflows without gambling with protected health information.
Clinical data and marketing data live under different laws, so they live in different zones — separated by schema at the data layer, not just by policy.
Governed by HIPAA
Human-operated.
Consent-driven.
Never automated.
Governed by Washington MHMDA
Nothing crosses between zones automatically. Every crossing is initiated by a human, backed by documented consent.
Clinical insights cross only as generic themes — "patients ask about thyroid panels" — never as identifiable patient data.
Patient photos require written marketing authorization plus a de-identification review before they can ever appear in Zone 2.
The two zones live in separate database schemas. The separation isn't a policy document people are asked to follow; it's a structural boundary the software physically cannot violate.
Most platforms bolt AI onto health data and hope for the best. ClinicSpark's clinical AI was built inside the compliance boundary from day one.
Clinical AI runs on AWS Bedrock under a signed Business Associate Agreement — the same legal framework that governs your EHR vendor.
AI endpoints retain nothing. Patient data is never stored by the model provider and never used to train models. Ever.
Every AI output is reviewed, editable, and approved by the clinician before it is saved. The AI drafts; the clinician decides.
HIPAA compliance breaks at the weakest link. Every vendor that touches PHI in ClinicSpark — hosting, platform engineering, AI, SMS, email — is covered by a Business Associate Agreement.
Cloud infrastructure operating under a signed BAA, with encryption in transit and at rest.
BAA CoveredThe team that builds and operates ClinicSpark works under BAA obligations, not just NDAs.
BAA CoveredAWS Bedrock clinical AI under signed BAA with zero data retention on every call.
BAA CoveredTwilio HIPAA-tier SMS for patient communications that may involve PHI.
BAA CoveredGoogle Workspace email operating under BAA for clinical correspondence.
BAA CoveredWhen an auditor asks "who saw this record and when," the answer should take seconds — not a forensic investigation.
Every meaningful action is recorded in an audit trail designed so that alterations are detectable.
Access is scoped to clinical roles, so staff see what their job requires — and nothing more.
Account security that assumes a busy clinic: shared workstations, interruptions, and shift changes.
Multi-tenant platforms share tables and trust filters to keep customers apart. ClinicSpark doesn't take that bet.
Each practice gets its own PostgreSQL database. No shared tables between customers — not filtered, separated.
Clinical and marketing data are isolated at the schema level inside each practice's own database.
Tamper-evident audit history retained for six years, matching the HIPAA documentation requirement.
Zero-data-retention AI endpoints mean patient data is never stored by, or trained into, any model.
All data is encrypted in transit and at rest. If another customer's data can't share a table with yours, an access-control bug can't leak it either.
Washington's My Health My Data Act treats consumer health data in marketing with near-HIPAA seriousness. ClinicSpark's marketing zone was built for it.
Prospect and marketing data — the people who downloaded your guide, asked about a service, or follow your clinic on social — is consumer health data under MHMDA. The marketing zone manages it with the consent machinery the law expects:
Consent is collected before consumer health data is used for marketing — built into the prospect intake itself, not appended later.
Consumers can withdraw consent, and the withdrawal takes effect across the marketing zone — not just one campaign list.
Every consent grant and withdrawal is recorded with a timestamp, so the practice can demonstrate compliance on request.
Opt-outs are managed centrally in the marketing zone, honored across email and campaign channels automatically.
We tell you exactly where things stand. ClinicSpark is architected for HIPAA and Washington MHMDA compliance, with BAA coverage across every PHI-touching vendor and enforcement built into the data layer. We don't wave certification logos we haven't earned — when third-party attestations are complete, you'll see them here with dates. If you want the details behind any claim on this page, ask us and we'll walk you through the architecture.
Bring your compliance officer, your privacy counsel, or just your hardest questions. We'll walk you through the Two-Zone Architecture, the BAA chain, and the audit trail — in plain language.
Compliance questions? Talk to us.Or email us directly: adam@impactme.ai