Legal

HIPAA Statement

Last updated: September 18, 2026

Scope

Pulse OS Health provides a care-coordination and performance platform that may process protected health information (PHI) on behalf of covered entities and their business associates, where a Business Associate Agreement (BAA) is in place.

Pulse OS is not a medical device and does not diagnose or treat disease. This statement describes how we approach HIPAA-aligned controls. It is not a certification badge and is not a substitute for a signed BAA.

Safeguards

Administrative: role-based access, identity verification against the identity provider, and least-privilege staff roles. Clinical records are excluded from coaching queries at fetch time.

Physical: cloud infrastructure with encrypted storage, private networking for the clinical store, and no public database address.

Technical: AES-256 encryption at rest, TLS 1.3 in transit, hashed identifiers in logs, and deletion that removes readings, features, and baselines rather than only the profile record.

Business Associate Agreements

A BAA is available on request for deployments that require one. We do not claim HIPAA certification, a completed HHS audit, or SOC 2 Type II until those documents exist.

Individual rights

Athletes and patients may access, correct, or request deletion of their information, and may withdraw sharing per staff role. Requests: privacy@pulseoshealth.com.

Privacy Notice·Security