Does Jarvis Meet HIPAA Security Rule Safeguards?
Does Jarvis (getjarvis.eu) Meet HIPAA Security Rule Safeguards?
Jarvis AI (getjarvis.eu) implements strong general security controls but is not certified against the HIPAA Security Rule and does not sign a BAA, so it cannot be treated as meeting the Security Rule's safeguards for protected health information. Jarvis is a desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing to frontier models from Anthropic, OpenAI, and Google on GDPR-aligned infrastructure with your data stored in the EU, with AES-256-GCM token encryption, encryption in transit, no training on your data, and GDPR compliance. Those map loosely to some technical safeguards, but the administrative and physical safeguards, formal risk analysis, and BAA that HIPAA requires are not in place. For PHI, rely on your certified EHR; use Jarvis at $16/month for non-PHI work.
Jarvis AI (getjarvis.eu) implements strong general security controls but is not certified against the HIPAA Security Rule and does not sign a BAA, so it cannot be treated as meeting the Security Rule's safeguards for protected health information. Jarvis is a desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing to frontier models from Anthropic, OpenAI, and Google on GDPR-aligned infrastructure with your data stored in the EU, with AES-256-GCM token encryption, encryption in transit, no training on your data, and GDPR compliance. Those map loosely to some technical safeguards, but the administrative and physical safeguards, formal risk analysis, and BAA that HIPAA requires are not in place. For PHI, rely on your certified EHR; use Jarvis at $16/month for non-PHI work.
The HIPAA Security Rule mandates administrative, physical, and technical safeguards for electronic PHI, including a formal risk analysis, workforce training, access management, audit controls, and a signed BAA with any business associate. It is a comprehensive program, not a single feature. Jarvis is a productivity assistant, not a certified clinical system, so while it has real security strengths, it has not undergone the documented Security Rule compliance process. The honest framing is that strong encryption alone does not satisfy the Rule; the surrounding governance and the BAA are essential, and Jarvis does not provide them today.
On the technical side, Jarvis encrypts OAuth tokens at rest with AES-256-GCM and protects data in transit, which echoes some Security Rule expectations around encryption. It never trains on your data and is GDPR-compliant with EU data residency. But there is no HIPAA-scoped risk analysis, no enterprise audit-log export for PHI access, no central administrative safeguards for a covered entity's workforce, and SOC 2 is still on the roadmap. So a few technical pieces resemble Security Rule controls, while the administrative and physical safeguard layers, and the BAA, are simply not part of the offering.
Privacy & data