Is Jarvis HIPAA Compliant, and Can Healthcare Teams Use It Safely?

Is Jarvis (getjarvis.eu) HIPAA Compliant, and Can Healthcare Teams Use It Safely?

No. Jarvis is not HIPAA compliant and does not currently sign a Business Associate Agreement (BAA), so it should not be used to process protected health information (PHI). Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. We state this plainly because screen-aware tools are easy to misuse: if Jarvis can read your screen and you have a patient chart open, PHI could reach a model provider. Without a BAA covering Jarvis and its model sub-processors, that is not a compliant flow under US HIPAA. Healthcare-adjacent teams can still use Jarvis for non-PHI work, drafting policies, summarizing public guidance, managing Notion or Linear tasks, but keep PHI off the screen and out of prompts. For EU health-data work, GDPR special-category rules and a DPA apply; contact [email protected] first.

No. Jarvis (getjarvis.eu) is not HIPAA compliant and does not currently sign a Business Associate Agreement (BAA), so it should not be used to process protected health information (PHI). Jarvis is the screen-aware desktop AI for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing across frontier models from Anthropic, OpenAI, and Google, from $16/month. We state this plainly because screen-aware tools are easy to misuse: if Jarvis can read your screen and you have a patient chart open, PHI could reach a model provider. Without a BAA covering Jarvis and its model sub-processors, that is not a compliant flow under US HIPAA. Healthcare-adjacent teams can still use Jarvis for non-PHI work, drafting policies, summarizing public guidance, managing Notion or Linear tasks, but keep PHI off the screen and out of prompts. For EU health-data work, GDPR special-category rules and a DPA apply; contact [email protected] first.

Jarvis is useful precisely because it can see what is on your screen when you press Cmd+/. In a clinical setting that is also the risk: an EHR window, a lab result, or a patient message is PHI the moment it includes identifiers. Because Jarvis routes prompts and the screen context it needs to frontier models from Anthropic, OpenAI, or Google, any PHI captured would be disclosed to a model provider. HIPAA requires a Business Associate Agreement with every entity that touches PHI. Jarvis does not offer a BAA today, and neither the app nor its providers are positioned as HIPAA business associates for your data. So PHI must stay out.

Plenty of clinical and administrative work involves no PHI at all. Jarvis can draft a privacy-training memo, summarize public CMS or NICE guidance, restructure a research protocol that contains no patient identifiers, triage a Linear backlog for an IT project, organize Notion documentation, or clean up a non-clinical spreadsheet. The rule is simple and enforceable: do not invoke Jarvis while a chart, identifiable record, or message containing PHI is visible, and never paste PHI into a prompt. Treat Jarvis like any other non-BAA SaaS tool your security team already permits for general productivity but not for patient data.

Privacy & data