The Quome platform services that may be used to store or transmit protected health information under the Quome Business Associate Addendum, and the security configuration each one requires.
This is the list referenced in Section 1.2 and Appendix A of the Business Associate Addendum (QUOME-LEGAL-BAA-002, version 2.0). Last updated 2026-09-11.
A Quome organization becomes a HIPAA Account when the customer designates it as containing PHI and executes the Business Associate Addendum for it in the Quome platform. Within that organization, PHI may be stored or transmitted only through the services listed below, configured as each row requires. Quome acts as a business associate for HIPAA Accounts only.
Quome's Bring Your Own Service Account architecture places all customer content, including ePHI, in the customer's own cloud account. Quome's control plane holds orchestration metadata and is not designed to store PHI. Because the underlying infrastructure is the cloud provider's, the customer must also hold a Business Associate Agreement with that provider before storing ePHI.
Services not listed on this page are not HIPAA Eligible Services and must not be used to store or transmit PHI, even within a HIPAA Account. Quome may add services at any time; a service is removed only with at least 90 days' notice, except where removal is required by an emergency, a third-party intellectual-property claim, or law.
Seven platform services, each eligible only when configured as shown.
Container deployment and management
Required configuration
Managed PostgreSQL (Cloud SQL)
Required configuration
Object storage (GCS/S3/Blob)
Required configuration
Secret management (Secret Manager)
Required configuration
Automated task orchestration
Required configuration
AI agent deployment and execution
Required configuration
End-user authentication
Required configuration
Any platform capability not listed here, for example interactive sandboxes, MCP tools and the model gateway, is not a HIPAA Eligible Service. Do not place PHI in it. Check this page before adopting a new service for PHI workloads.
Section 4.3 of the Addendum. The customer is responsible for configuring every HIPAA Account this way.
Encrypt all PHI stored in or transmitted using the Services in accordance with the HHS Secretary's guidance on rendering unsecured PHI unusable, unreadable or indecipherable to unauthorized individuals.
Configure role-based access control in the Quome platform, assign the minimum necessary permissions to each user, and enable multi-factor authentication for every user with access to PHI.
Enable and retain audit logs for the HIPAA Account at the maximum retention level the platform supports; never disable or reduce audit logging below the default.
Do not store or transmit PHI using any Quome service that is not designated on this page.
Configure network access controls, IP allowlists and VPN requirements appropriate to the sensitivity of the PHI being processed.
HIPAA Eligible Services run on the customer's own cloud account. Quome's Addendum does not extend to, replace or satisfy the cloud provider's requirements, so a BAA with the provider must be in place before any ePHI is stored (Section 4.2).
Subprocessor categories and their PHI access are set out in Appendix B of the Addendum.
| Provider | BAA | How to obtain |
|---|---|---|
| Google Cloud | Available | Accept via Cloud Console or contact Google Cloud sales |
| AWS | Available | Accept via AWS Artifact |
| Azure | Available | Included in Microsoft Online Services Terms |
Execute the Business Associate Addendum for your organization from the platform's compliance settings. Legal documents, including the Terms of Service and Privacy Notice, are in the Legal Center.
HIPAA compliance is a shared responsibility. This page describes which services are eligible and how they must be configured; it is not legal advice and does not by itself ensure compliance. Consult qualified counsel for your organization's obligations.