05Security & accountability

Answers, not a badge.

Written to be forwarded. If your practice manager or counsel wants this in a document, ask and we will send it, but nothing here should be a surprise to them by then.

Clinical accountability

It stays with you.

Nobody at Jeni answers a clinical question. Every clinical decision routes to your clinician, against a protocol your clinician wrote and signed. We run the software; the medicine is yours.

This is the answer to the question physicians say they care most about before adopting any new tool, and it is deliberately structural rather than procedural. Because we provide administrative and communication support under your direction and no clinical services, corporate-practice-of-medicine restrictions, state licensure and scope-of-practice questions do not attach to us, and clinical liability stays where it already sits, with the treating clinician.

Every instruction traces to a signatureA named clinician recorded that plan, at that dose, on that date. Protocol versions are logged, so it is always answerable which version a given patient was on.
There is nothing we could say in your nameThe only thing that reaches a patient is the plan a clinician recorded and its 140-character instruction. No message channel exists, so the failure where a vendor answers a clinical question because it seemed obvious is closed structurally rather than by policy.
Nothing is monitoredRecords move when the patient opens the app. Jeni raises no alerts and notices no silence, and the product tells both the clinician and the patient so. Urgent concerns go through the practice's usual pathways.
Data

Where it sits, and who can reach it.

Encrypted at rest and in transitWith role-based access enforced server-side: owners manage the team, clinicians assign care, staff invite patients and read records and can never author a medication plan.
Every access logged, and shown to the patientAn audit row for each open and each change, and the patient's copy of that trail is the same list, not a redacted one. It is the control we would most want as a patient, so it is the one we built first.
No patient data in analytics or error trackingOperational events carry single tokens only: a kind, a code, a build. The schema cannot carry a medication name, a weight or a symptom. The telemetry boundary is designed before the code, not retrofitted; product analytics and crash reporting are the unglamorous way health data leaks.
No model between the patient and your pageThe interval read is computed deterministically from the record, on the patient's own device. Nothing a clinician reads in Jeni Care has passed through a language model.
Where we actually are

Pre-pilot, and the list is not finished.

This is the section most vendors write in the future tense. Here it is in the present, because a clinician can check it and because the gap is the reason our ask is twenty minutes and not a contract.

No real patient record has been in JeniNot one. Every patient in the demo clinic is fictional and every record in it was generated. That is a deliberate gate, not a stage we have not reached yet.
The business associate agreement is not draftedIt has to be, with counsel, before a first real patient, along with a services agreement stating plainly that we provide administrative support under the practice's direction and no clinical services. We would rather name that here than let you assume a document exists.
We do not hold SOC 2SOC 2 Type II belongs in the year a signed contract requires it. Saying so is cheaper than implying a certification we do not have, and you would find out anyway.
Production infrastructure for real records is not builtThe demo you can open runs against a recording. Standing up an environment that could hold protected health information, and having counsel review it, is on the list ahead of any first patient.

What a practice would be agreeing to in the meantime is a conversation and, at most, a letter of intent describing a first cohort that begins when those gates close. Nothing about a pilot starts before they do.

Language

Why we never say “HIPAA compliant”.

Because there is no such certification. HHS endorses no private HIPAA certification program, so a vendor claiming to be “HIPAA compliant” or “HIPAA certified” is describing an audit they bought, not a status that exists. So we do not use the phrase at all, in either direction: we describe the safeguards that exist, and name the ones that do not yet.

A related point that matters more for cash-pay practices than most vendors admit: a clinic that never transmits health information electronically in connection with a covered transaction may not be a HIPAA covered entity at all. That does not make the question disappear. State medical privacy law, state consumer health data law, medical records retention rules and the FTC’s health breach notification rule can all still apply, and several of them have no size threshold and no HIPAA exemption. Our posture is therefore built on consent and on the safeguards above rather than on an exemption that may not be yours to claim.

This is a description of how we work, not legal advice. Your counsel should reach their own view.

Exit

Your data leaves with you.

A full export, on request, at any timeNot a report. The record: enrollments, the plans and protocol versions each patient ran, what the patient entered, and the access log.
Deletion on request when we stop working togetherSubject to the retention periods your state imposes on the practice, which are usually longer than either of us would choose.
The protocol you wrote stays yoursWe do not claim ownership of a clinic's pathway, and we do not resell it as a template.
Talk to us

Send this to your counsel.

If something here does not answer the question your practice manager will ask, tell us which question and we will answer it plainly.