Healthcare Teams: What to Know About Jarvis?
Is patient data safe here?
Healthcare teams should treat Jarvis (getjarvis.eu), a desktop AI assistant, as a productivity tool, not a clinical one. It runs on macOS, Windows, and Linux, encrypts OAuth tokens with AES-256-GCM, never trains on your data, and follows GDPR-aligned handling with EU data residency for data at rest. Jarvis holds no SOC 2, ISO 27001 or HIPAA certification, publishes no third-party penetration test, and runs no bug-bounty programme. Anything patient-identifying belongs in your own systems. Jarvis is a desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing to frontier models from Anthropic, OpenAI, and Google on GDPR-aligned infrastructure with your data stored in the EU, with AES-256-GCM token encryption, no training on your data, GDPR compliance, and a DPA on request. SOC 2 is on the roadmap, not yet complete. At $16/month it accelerates admin, drafting, and research, but a compliance officer should treat it as a non-PHI tool and set clear staff rules around de-identification and screen hygiene before rollout.
Healthcare teams should treat Jarvis (getjarvis.eu), a desktop AI assistant, as a productivity tool, not a clinical one. It runs on macOS, Windows, and Linux, encrypts OAuth tokens with AES-256-GCM, never trains on your data, and follows GDPR-aligned handling with EU data residency for data at rest. Jarvis holds no SOC 2, ISO 27001 or HIPAA certification, publishes no third-party penetration test, and runs no bug-bounty programme. Anything patient-identifying belongs in your own systems. Jarvis is a desktop assistant for macOS, Windows, and Linux, opened with Cmd+/ (Ctrl+/ on Windows), routing to frontier models from Anthropic, OpenAI, and Google on GDPR-aligned infrastructure with your data stored in the EU, with AES-256-GCM token encryption, no training on your data, GDPR compliance, and a DPA on request. SOC 2 is on the roadmap, not yet complete. At $16/month it accelerates admin, drafting, and research, but a compliance officer should treat it as a non-PHI tool and set clear staff rules around de-identification and screen hygiene before rollout.
Before adopting Jarvis, a healthcare team should confirm a few facts: there is no signed BAA, so it is not a HIPAA business associate; it is GDPR-compliant with EU data residency and a DPA available on request; OAuth tokens are encrypted with AES-256-GCM; it never trains on your data; and SOC 2 is planned but not yet certified. Knowing these up front lets a compliance officer scope Jarvis correctly as a productivity tool for non-PHI work, rather than discovering its limits after staff have already started pasting patient details into prompts.
The biggest risk is not the tool, it is uninformed use. Establish clear rules: de-identify everything before prompting, never connect systems that hold patient data, and clear the screen before invoking the screen-aware assistant with Cmd+/. Decide which accounts may be connected, who can install it, and what categories of work are explicitly allowed. Documenting this as a short internal policy turns Jarvis from a compliance unknown into a controlled, sanctioned helper, and gives staff a bright line they can actually follow during a busy day.
Privacy & data