Valorenode Documentation

HIPAA Compliance Statement

Business Associate Agreements, strict PII isolation, and encrypted review streaming logs for regulated healthcare-adjacent operations.

Last updated: July 12, 2026

1. Scope & Applicability

Valorenode LDA, headquartered in Lisbon, Portugal, provides review intelligence infrastructure that may process Protected Health Information (PHI) when healthcare-adjacent organizations use our platform. This statement defines our obligations under HIPAA when operating as a Business Associate (BA) to Covered Entities and their subcontractors.

2. Business Associate Agreements (BAAs)

Valorenode executes standardized BAAs prior to any production deployment where PHI may enter the review pipeline. Each BAA specifies permitted uses, disclosure limitations, safeguard requirements, breach notification timelines (within 72 hours of confirmed discovery), and subcontractor accountability chains. BAAs are countersigned by our Data Protection Officer and stored in our encrypted compliance vault with immutable audit timestamps.

3. Strict PII Isolation

All tenant data is isolated via Supabase Row-Level Security (RLS) with FORCE policies enabled on every table. PHI fields are segregated into dedicated encrypted columns using AES-256-GCM envelope encryption with per-organization data keys rotated every 90 days. Cross-tenant queries are architecturally impossible at the database layer — application code cannot override RLS without the audited service-role pathway.

  • Organization-scoped JWT claims enforce access at query time
  • AI prompt pipelines strip PHI before transmission to OpenAI gateways
  • ENFORCE_GDPR_DATA_MASKING redacts residual identifiers in all exports

4. Encrypted Review Streaming Logs

When ENFORCE_HIPAA_LOGGING is active, every review ingestion, AI draft generation, human approval, and outbound response event is written to an append-only audit stream. Logs are encrypted in transit (TLS 1.3) and at rest (AES-256), with log payloads containing action metadata only — never raw review body text or patient identifiers. Streaming logs are retained for 7 years per BAA schedule and are exportable for OCR audits on request.

5. Breach Notification

Valorenode maintains a 24/7 incident response protocol. Confirmed breaches involving PHI trigger immediate containment, forensic analysis, and notification to affected Covered Entities within 72 hours per HIPAA §164.410. All incidents are logged to our internal trust register maintained in our Portuguese operations center.