Blog / Questions / FIG. 130
Is Jev HIPAA Compliant?
Is Jev HIPAA compliant? We found no public claim either way. The BAA question to ask, how to design around PHI, and the audit posture to keep.
We can't tell you, and neither can anyone except TypeSafe AI. At the time of writing we haven't found a public HIPAA statement or Business Associate Agreement (BAA) offering for Jev, TypeSafe AI's decision model, in the sources we track. That is not the same as "no": it means the answer lives with the vendor, at docs.typesafe.ai or through their sales and security contacts.
Also worth saying plainly: a model isn't "HIPAA compliant" on its own. Compliance is a property of your whole arrangement (contracts, safeguards, access controls, logging), and a vendor's willingness to sign a BAA is one piece of it. This page is not legal advice, and we mean that.
The questions to bring to TypeSafe AI
If your pipeline would send protected health information (PHI), your compliance team needs written answers to:
- Will TypeSafe AI sign a BAA covering Jev API usage?
- What are retention and training-use terms for request data?
- Where is data processed, and which subprocessors touch it? If you reach Jev through an intermediary such as the Vercel AI Gateway (the access path described in ecosystem documentation), that party belongs in the same review.
- What certifications or audit reports can they share?
No signed BAA, no PHI. That rule is boring and it's the whole game.
Designing so PHI never has to leave
Many healthcare-adjacent verdicts don't need identifiable data at all. De-identify before transit, send only the fields a question requires, and keep perception local; the security and privacy page owns those patterns. What stays mandatory in healthcare: a human makes every clinical or coverage decision, and every verdict is logged with its question version, confidence, and reviewer, which is the audit trail the verdict-logging guide describes.
The public receipts in health are early and non-clinical. A health-video search tool reports retrieval accuracy rising from 67% with embeddings alone to 75% with embeddings plus Jev, as reported (build). A small Korean/English study including medical-text questions describes itself as "not a clinical validation" (build). Useful signals, not evidence for clinical use.
Frequently asked questions
Is Jev HIPAA compliant?
We found no public HIPAA or BAA statement from TypeSafe AI at the time of writing; ask them directly and get the answer in writing before sending any PHI.
Can I use Jev in a healthcare app without a BAA?
Only for workloads that contain no PHI, such as de-identified or non-patient data. Your compliance and legal teams make that call; this is not legal advice.
Can Jev make clinical decisions?
It shouldn't. Jev verdicts can support triage or routing, but clinical decisions need a qualified human, with verdicts logged per the audit-trail guide.
What should healthcare teams log?
The question version, verdict, confidence, and the human who acted on it, with PHI excluded or redacted from the log itself; the PII page covers minimization.
Numbers throughout are as reported by the build authors, not verified by shipwithjev. Code-shaped examples are pseudocode; the official docs live at docs.typesafe.ai.