Compliance

HIPAA Eligible Services

The Quome platform services that may be used to store or transmit protected health information under the Quome Business Associate Addendum, and the security configuration each one requires.

This is the list referenced in Section 1.2 and Appendix A of the Business Associate Addendum (QUOME-LEGAL-BAA-002, version 2.0). Last updated 2026-09-11.

What "HIPAA Eligible" means

A Quome organization becomes a HIPAA Account when the customer designates it as containing PHI and executes the Business Associate Addendum for it in the Quome platform. Within that organization, PHI may be stored or transmitted only through the services listed below, configured as each row requires. Quome acts as a business associate for HIPAA Accounts only.

Quome's Bring Your Own Service Account architecture places all customer content, including ePHI, in the customer's own cloud account. Quome's control plane holds orchestration metadata and is not designed to store PHI. Because the underlying infrastructure is the cloud provider's, the customer must also hold a Business Associate Agreement with that provider before storing ePHI.

Services not listed on this page are not HIPAA Eligible Services and must not be used to store or transmit PHI, even within a HIPAA Account. Quome may add services at any time; a service is removed only with at least 90 days' notice, except where removal is required by an emergency, a third-party intellectual-property claim, or law.

Appendix A

Designated services

Seven platform services, each eligible only when configured as shown.

Not currently designated

Any platform capability not listed here, for example interactive sandboxes, MCP tools and the model gateway, is not a HIPAA Eligible Service. Do not place PHI in it. Check this page before adopting a new service for PHI workloads.

Required security configurations

Section 4.3 of the Addendum. The customer is responsible for configuring every HIPAA Account this way.

§4.3.1

Encryption

Encrypt all PHI stored in or transmitted using the Services in accordance with the HHS Secretary's guidance on rendering unsecured PHI unusable, unreadable or indecipherable to unauthorized individuals.

§4.3.2

Access controls

Configure role-based access control in the Quome platform, assign the minimum necessary permissions to each user, and enable multi-factor authentication for every user with access to PHI.

§4.3.3

Audit logging

Enable and retain audit logs for the HIPAA Account at the maximum retention level the platform supports; never disable or reduce audit logging below the default.

§4.3.4

HIPAA Eligible Services only

Do not store or transmit PHI using any Quome service that is not designated on this page.

§4.3.5

Network security

Configure network access controls, IP allowlists and VPN requirements appropriate to the sensitivity of the PHI being processed.

Your cloud provider's BAA

HIPAA Eligible Services run on the customer's own cloud account. Quome's Addendum does not extend to, replace or satisfy the cloud provider's requirements, so a BAA with the provider must be in place before any ePHI is stored (Section 4.2).

Subprocessor categories and their PHI access are set out in Appendix B of the Addendum.

ProviderBAAHow to obtain
Google CloudAvailableAccept via Cloud Console or contact Google Cloud sales
AWSAvailableAccept via AWS Artifact
AzureAvailableIncluded in Microsoft Online Services Terms

Ready to designate a HIPAA Account?

Execute the Business Associate Addendum for your organization from the platform's compliance settings. Legal documents, including the Terms of Service and Privacy Notice, are in the Legal Center.

HIPAA compliance is a shared responsibility. This page describes which services are eligible and how they must be configured; it is not legal advice and does not by itself ensure compliance. Consult qualified counsel for your organization's obligations.