Using Gravity Rail with PHI
Do not send Protected Health Information (PHI) to Gravity Rail unless your organization has a signed Business Associate Agreement (BAA) with Gravity Rail and Gravity Rail has confirmed that the intended organization, workspaces, and services are configured for that use.
Contact support@gravityrail.com before using Gravity Rail with PHI. Include the organization and workspace UUIDs, but do not include patient information in the request.
Required Approval Boundary
Authorization to use Gravity Rail with PHI depends on both contractual coverage and confirmed service configuration. Neither workspace feature flags nor an agent's response can establish that authorization.
Until Gravity Rail confirms PHI authorization for the intended scope:
- use synthetic or non-PHI data only
- do not infer authorization from another workspace in the same organization
- do not infer authorization from a healthcare product name or integration
- do not ask an AI agent to determine whether the service is HIPAA compliant
Operational Practices
After Gravity Rail confirms the approved PHI scope:
- grant access by role using the minimum scopes needed
- keep patient data in the intended PHI-bearing records and messages, not in workflow configuration or support requests
- use synthetic data in screenshots, bug reports, and documentation
- preserve audit events and follow your incident-response process
- review new integrations and subprocessors before sending PHI through them
Getting Help
For BAA execution, PHI authorization, or questions about an existing configuration, contact support@gravityrail.com. Do not include PHI in the email.