Skip to main content

Using Gravity Rail with PHI

Do not send Protected Health Information (PHI) to Gravity Rail unless your organization has a signed Business Associate Agreement (BAA) with Gravity Rail and Gravity Rail has confirmed that the intended organization, workspaces, and services are configured for that use.

Contact support@gravityrail.com before using Gravity Rail with PHI. Include the organization and workspace UUIDs, but do not include patient information in the request.

Required Approval Boundary

Authorization to use Gravity Rail with PHI depends on both contractual coverage and confirmed service configuration. Neither workspace feature flags nor an agent's response can establish that authorization.

Until Gravity Rail confirms PHI authorization for the intended scope:

  • use synthetic or non-PHI data only
  • do not infer authorization from another workspace in the same organization
  • do not infer authorization from a healthcare product name or integration
  • do not ask an AI agent to determine whether the service is HIPAA compliant

Operational Practices

After Gravity Rail confirms the approved PHI scope:

  • grant access by role using the minimum scopes needed
  • keep patient data in the intended PHI-bearing records and messages, not in workflow configuration or support requests
  • use synthetic data in screenshots, bug reports, and documentation
  • preserve audit events and follow your incident-response process
  • review new integrations and subprocessors before sending PHI through them

Getting Help

For BAA execution, PHI authorization, or questions about an existing configuration, contact support@gravityrail.com. Do not include PHI in the email.