HIPAA Compliance
WoundIQ is built for use inside licensed healthcare facilities. This page explains how NorthStar Technology Services LLC safeguards Protected Health Information as a Business Associate under HIPAA, the HITECH Act, and applicable state privacy laws.
Effective August 16, 2026 · Version 1.0 · NorthStar Technology Services LLC
1Our Role as a Business Associate
WoundIQ handles Protected Health Information ("PHI") as defined under the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and applicable state privacy laws.
Healthcare facilities that use WoundIQ are Covered Entities. NorthStar Technology Services LLC operates as a Business Associate to those facilities: we create, receive, maintain, and transmit PHI on their behalf, and we are directly liable under HIPAA for doing so in accordance with the Privacy, Security, and Breach Notification Rules.
A note on terminology. There is no official government certification for HIPAA compliance, and any vendor claiming to be "HIPAA certified" is describing a third-party assessment rather than a regulatory approval. What we can state is what appears on this page: the safeguards we implement, the contractual commitments we make, and the obligations we accept as a Business Associate.
HIPAA compliance is a shared responsibility. We are responsible for the safeguards built into the platform; your facility remains responsible for workforce training, role assignment, access reviews, and the policies governing how your staff use the system.
2Business Associate Agreements
Our U.S.-based facility customers are required to execute a Business Associate Agreement (BAA) with NorthStar Technology Services LLC before PHI is placed into the platform. The BAA sets out the permitted uses and disclosures of PHI, our safeguard obligations, breach notification duties, and the handling of PHI on termination.
To request a copy of our standard BAA, contact sales@woundiq.ai.
3What PHI WoundIQ Processes
PHI is entered into WoundIQ by your authorized clinical staff in the course of patient care. It includes:
- Wound assessments and clinical observations — including vitals, care plans, and assessment history.
- Clinical scoring data — including PUSH Score, Braden Scale, and MNA nutritional assessment results.
- Wound photographs — uploaded during assessments for clinical documentation and, optionally, AI-assisted analysis. Images are linked to a specific patient record.
- Clinical notes and dictation — free-text observations, including those captured via voice dictation. Voice dictation is processed by your browser's built-in speech recognition and the audio is not transmitted to or stored by WoundIQ.
PHI is never used for marketing, sales, advertising, or model training outside the scope of the contracted service to your facility, and is never sold.
4Administrative Safeguards
- Business Associate Agreements executed with every U.S. facility customer, and with subcontractors that may encounter PHI.
- Role-based authorization model — the platform defines distinct roles (Admin, Scheduler, Clinician, Nurse, Patient), and your facility designates which role each member of your workforce holds.
- Confidentiality obligations binding NorthStar employees and contractors who may have access to customer data.
- Incident response — defined procedures for investigating and escalating suspected unauthorized access, coordinated with your facility's Privacy Officer.
5Physical Safeguards
WoundIQ runs on enterprise cloud infrastructure located in the United States. Physical access to the data centers housing PHI is controlled by the infrastructure provider under their own certified physical security program, which includes controlled facility access, environmental controls, and media disposal procedures. NorthStar personnel have no physical access to those facilities.
6Technical Safeguards
- Encryption in transit — all communication between your browser or device and WoundIQ servers is encrypted using industry-standard TLS.
- Encryption at rest — data stored within WoundIQ's infrastructure, including wound images, is encrypted at rest.
- Secure credential storage — user passwords are hashed with Argon2id, a memory-hard, OWASP-recommended algorithm. Passwords cannot be retrieved or reversed.
- Session management — authentication uses short-lived, time-limited tokens with a short access-token lifetime and a separate refresh token, rather than long-lived sessions or tracking cookies.
- Rate limiting — authentication endpoints are rate limited to resist credential-stuffing and brute-force attempts.
- Automatic logoff — users are encouraged to log out on shared or public devices, and token expiry limits the window of an unattended session.
7Tenant Isolation & Access Control
All PHI is strictly scoped to the healthcare facility that created it. No patient data is ever shared across facilities.
- A tenant identifier is embedded in every authenticated session and enforced at the database level on every query — isolation is not left to application-layer discretion.
- Middleware rejects any request that attempts to reach data outside the caller's tenant, and administrative tokens are blocked from clinical routes entirely.
- Row-level scoping applies within a facility as well: clinicians see only their assigned patients, and patients see only their own record.
- Every route declares the roles permitted to reach it, and access rights are evaluated on each request rather than only at login.
8Audit Controls
WoundIQ records user activity — which screens and features are accessed, actions performed, and timestamps of key events — linked to the acting user account, to support security monitoring and compliance review by your facility's privacy or compliance team.
Clinical records additionally carry attribution metadata identifying the user who created and last updated each entity, and assessment workflow state is enforced server-side so that clinical sign-off cannot be bypassed by a client.
Users should understand that their actions within the platform are logged and may be reviewed for compliance or audit purposes.
9Breach Notification
In the event of a breach of unsecured PHI, NorthStar Technology Services LLC will notify the affected Covered Entity without unreasonable delay and within the timeframes required by the HIPAA Breach Notification Rule and the terms of the applicable BAA. Our notification will describe what occurred, the PHI involved, the steps taken, and our mitigation measures.
If you suspect a breach or unauthorized access, notify your facility's designated Privacy Officer immediately and contact us at sales@woundiq.ai. Do not include PHI in your message to us.
10Subcontractors & AI Processing
We engage trusted third-party providers to support the operation of WoundIQ, including cloud infrastructure and image storage. Subcontractors that may encounter PHI are bound by confidentiality obligations and, where required, their own Business Associate Agreements.
AI-assisted analysis. When the optional AI wound image analysis feature is used, wound images are transmitted to a third-party AI service for analysis under a Business Associate Agreement. Images are not retained by that provider for model training or for any purpose other than returning the analysis result. AI training data is segregated from clinical records, and any AI-assisted output is a suggestion for clinician review that must be confirmed by a qualified clinician before it is acted upon.
Health information exchange. If your facility enables WoundIQ's interoperability features, clinical data may be shared with authorized health systems or applications as directed by your facility's integration configuration.
11Minimum Necessary & Workforce Responsibilities
Access is granted on a minimum-necessary basis through the role and scoping controls described above. Each authorized user who accesses PHI through WoundIQ acknowledges that:
- They are authorized by their facility to access the medical records and PHI maintained in the system, and use the system solely for the purposes they are designated for.
- They will hold all PHI in strict confidence and use it only for authorized clinical and administrative purposes related to patient care.
- They will not directly or indirectly use, disclose, copy, transfer, or allow unauthorized access to PHI.
- They will promptly report any suspected unauthorized access or data breach to their facility's Privacy Officer.
- Unauthorized use or disclosure of PHI may result in civil and criminal penalties under HIPAA and applicable state laws.
12Patient Rights Under HIPAA
Patients hold rights over their health information — including rights of access, amendment, an accounting of disclosures, and restriction requests. Because your facility is the Covered Entity responsible for the patient record, patient requests should be directed to the facility in the first instance, not to NorthStar.
NorthStar will cooperate with facility requests to fulfill these obligations, including producing, amending, or deleting records held on the facility's behalf.
13Retention & Secure Disposal
WoundIQ retains data for as long as your facility's account is active, and for a minimum period thereafter as required by applicable law, regulatory guidance, or the terms of your facility's service agreement. Specific retention periods are defined in your facility's contract.
On termination, NorthStar provides a reasonable period for the facility to export its data before it is securely deleted. Data is destroyed in a manner that prevents reconstruction or recovery.
14This Website Does Not Collect PHI
woundiq.ai is a marketing website and is not a HIPAA-regulated channel. The demo request form is a commercial enquiry channel routed to our sales team — it is not an appropriate or secure destination for patient information.
Please do not submit PHI, patient identifiers, or clinical data through the form or by email. Information submitted through this website is handled under our Privacy Policy.
15Contact & Privacy Officer
For HIPAA-related enquiries, BAA requests, or to report a suspected data breach, contact us — and also notify your facility's designated Privacy Officer. Do not include any PHI in your message.
- Email: sales@woundiq.ai
- Phone: +1 (847) 812-0026
- Post: NorthStar Technology Services LLC, 2525 Cabot Dr, Suite 201, Lisle, IL 60532, USA
See also our Privacy Policy and Terms & Conditions.
© 2026 NorthStar Technology Services LLC. All rights reserved. Questions about this document? Email sales@woundiq.ai.