Legal

HIPAA & Business Associate Commitments

Effective date: July 25, 2026 · Last updated: July 25, 2026

1. Our role under HIPAA

When Alli Health performs care-management support services on behalf of a healthcare practice, Alli acts as a Business Associate as defined by the Health Insurance Portability and Accountability Act (HIPAA). The practice remains the Covered Entity and the steward of its patients' relationships and clinical decisions.

2. Business Associate Agreements

Alli enters into a written Business Associate Agreement (BAA) with every practice customer before receiving or processing any protected health information (PHI). Our BAA addresses permitted uses and disclosures, safeguards, subcontractor flow-down, breach notification, and PHI return or destruction at termination. Practices can request our standard BAA at hello@allihealth.ai.

3. How we handle PHI

4. Breach notification

In the event of a breach of unsecured PHI, Alli will notify affected practice customers without unreasonable delay and within the timeframes required by the HITECH Act and our BAAs, and will cooperate fully in any required notifications and remediation.

5. Security program

Alli maintains an information-security program aligned to the HIPAA Security Rule, including risk assessments, workforce training, incident response procedures, and vendor review. A SOC 2 examination is in progress.

6. For patients

If you are a patient enrolled in an APCM program supported by Alli, your healthcare practice's Notice of Privacy Practices governs how your health information is used and describes your rights (including access, amendment, and accounting of disclosures). Please direct privacy requests to your practice; we support practices in fulfilling them.

7. Contact

Privacy and security questions: hello@allihealth.ai.