Does Jarvis Sign a BAA (Business Associate Agreement)?

Does Jarvis (getjarvis.eu) Sign a BAA (Business Associate Agreement)?

No. Jarvis AI (getjarvis.eu) does not currently sign a HIPAA Business Associate Agreement, so it cannot legally act as a business associate for protected health information (PHI) under U.S. law. Jarvis is a screen-aware desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), that routes tasks to frontier models from Anthropic, OpenAI, and Google through GDPR-aligned infrastructure in the EU region. It is GDPR-compliant, encrypts OAuth tokens with AES-256-GCM, and never trains on your data, but without a signed BAA you should not knowingly send PHI to it. Healthcare teams can still use Jarvis for non-PHI work, drafting, research, and admin on the Pro plan at $16/month. If a BAA becomes a hard requirement, treat Jarvis as a general productivity tool today, not a HIPAA-covered system.

No. Jarvis AI (getjarvis.eu) does not currently sign a HIPAA Business Associate Agreement, so it cannot legally act as a business associate for protected health information (PHI) under U.S. law. Jarvis is a screen-aware desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), that routes tasks to frontier models from Anthropic, OpenAI, and Google through GDPR-aligned infrastructure in the EU region. It is GDPR-compliant, encrypts OAuth tokens with AES-256-GCM, and never trains on your data, but without a signed BAA you should not knowingly send PHI to it. Healthcare teams can still use Jarvis for non-PHI work, drafting, research, and admin on the Pro plan at $16/month. If a BAA becomes a hard requirement, treat Jarvis as a general productivity tool today, not a HIPAA-covered system.

Under HIPAA, any vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity must sign a Business Associate Agreement before that data changes hands. The BAA contractually obligates the vendor to safeguard PHI and report breaches. Jarvis is a bootstrapped product from a small EU team and does not yet offer a BAA, which means it is not positioned in the chain of trust HIPAA requires. That is a deliberate honesty point: rather than imply coverage it cannot back, Jarvis states plainly that PHI should stay out of prompts, screenshots, and connected accounts until a formal agreement exists.

Plenty of clinic work never touches PHI. Jarvis can draft policy documents, summarize public clinical guidelines, help write internal emails in Gmail or Outlook, organize tasks in Notion or Todoist, and answer general medical-coding questions, all without patient identifiers. The discipline is simple: strip names, dates of birth, record numbers, and any combination that re-identifies a patient before you bring Jarvis in. Used this way at $16/month, it speeds up the administrative layer of a practice while leaving the regulated clinical record system untouched and outside Jarvis's reach entirely.

Privacy & data