Health data & HIPAA
The current service is not offered for protected health information.
1. No PHI or regulated clinical use #
EIZO is not currently offered as a HIPAA-enabled service. No Business Associate Agreement (BAA) is offered by this deployment. Do not upload or process protected health information (PHI), identifiable patient records, medical images containing patient identifiers, or other regulated clinical data. This restriction applies to prompts, filenames, reference media, metadata and generated outputs as well as source files.
This service is not intended for medical diagnosis, treatment, emergency response or clinical decisions. Fictional or educational creative content is different from submitting real patient information; removing a name alone does not establish that a record is properly de-identified.
2. Why encryption is not enough #
HHS explains that a cloud provider maintaining ePHI can be a business associate even when the provider cannot decrypt it. Appropriate BAAs and required safeguards are necessary for covered use. Encryption, a private node or a consent checkbox alone does not make this deployment HIPAA compliant.
3. Any future regulated offering #
A future health-data offering would require a separate documented assessment, suitable contracts including BAAs where required, approved hosting and subprocessors, access restrictions, audit and incident controls, retention and disposal procedures, workforce processes and ongoing risk management. Public volunteer GPU nodes must not be used for such data through the current service.
If sensitive patient information is uploaded accidentally, stop further processing and seek help through the operator’s established support channel. Do not spread it across additional nodes or attach the records to a public report. A dedicated privacy/security contact is pending and must be established before final publication.
Official references
Reference material informs this draft; it does not certify the service.