Compliance

HIPAA Compliance

Effective date: March 1, 2026 · Last updated: March 1, 2026

Vivy takes the privacy and security of health information seriously. This page describes how we comply with HIPAA and protect your Protected Health Information (PHI).

HIPAA CompliantBAA AvailableSOC 2-alignedAES-256 EncryptionFirebase BAA signed

1. Overview

Vivy, Inc. ("Vivy") is committed to complying with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations, including the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

Vivy operates as a Business Associate for covered entities that use our platform. Where applicable, we enter into a Business Associate Agreement (BAA) that defines the permissible uses and disclosures of Protected Health Information (PHI).

2. What constitutes PHI on Vivy

Protected Health Information (PHI) on Vivy may include: biomarker measurements, protocol logs, medication and supplement records, health goals, and any other individually identifiable health information you enter into the app.

PHI is stored under your authenticated user ID in Firebase Firestore and is governed by our Firestore security rules, which enforce strict user-level isolation.

3. Use and disclosure of PHI

Permitted uses. We use PHI only to provide the Vivy service — including protocol tracking, AI-powered health recommendations, and biomarker analysis — and as otherwise permitted by our BAA and HIPAA.

No sale of PHI. We do not sell, rent, or otherwise monetize PHI.

Minimum necessary. We apply the HIPAA minimum necessary standard, limiting access to PHI to what is required to perform a specific function.

Third-party AI services. We do not send raw PHI to third-party AI model providers. AI inference that may involve PHI is performed within our own Firebase Cloud Functions environment, under BAA coverage.

4. Your rights as a patient

Under HIPAA, you have the right to access your PHI, request corrections, receive an accounting of disclosures, and request restrictions on use.

To exercise any HIPAA right, contact our Privacy Officer at support@heyvivy.com. We will respond within the timeframes required by HIPAA (generally 30 days, with one possible 30-day extension).

You may also delete your account and all associated PHI at any time through the app (Settings → Account → Delete Account).

5. Breach notification

In the event of a breach of unsecured PHI, we will notify affected individuals, the Secretary of the U.S. Department of Health and Human Services (HHS), and, where applicable, the media — within the timeframes required by the HIPAA Breach Notification Rule.

We maintain an incident response plan that is reviewed and tested annually. Our team is trained to identify and escalate potential breaches immediately.

6. Business Associate Agreements

Vivy signs BAAs with covered entities that require them before any PHI is shared. We also maintain signed BAAs with our key infrastructure providers, including Google Cloud (Firebase).

To request a BAA with Vivy, or to obtain a copy of our BAA template, contact support@heyvivy.com.

7. Complaints

If you believe your HIPAA rights have been violated, you may file a complaint with our Privacy Officer at support@heyvivy.com or directly with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr.

We will not retaliate against any individual for filing a good-faith complaint.

Security safeguards

How we protect your data

Administrative safeguards

  • Designated HIPAA Security Officer
  • Workforce training on PHI handling policies
  • Access controls and minimum necessary standard
  • Business Associate Agreements (BAAs) with all relevant vendors
  • Incident response and breach notification procedures
  • Regular risk assessments and policy reviews

Physical safeguards

  • All PHI stored in Google Cloud infrastructure (Firebase), which maintains SOC 2 Type II and ISO 27001 certifications
  • No on-premises servers; no physical access to infrastructure by Vivy employees
  • Workstation access controls and device management policies for team members

Technical safeguards

  • End-to-end encryption in transit (TLS 1.3) and at rest (AES-256)
  • Firestore security rules enforce per-user data isolation
  • Firebase Authentication with secure token management
  • Audit logging of all PHI access events
  • Automatic session expiration and re-authentication requirements
  • Role-based access controls limiting internal access to PHI

Need a Business Associate Agreement?

Covered entities requiring a BAA before using Vivy can request one at the address below. We typically turn these around within 3 business days.

Request a BAA →