Skip to main content
Compliance posture

HIPAA, honestly.

Where we are right now: WithDave is not yet a HIPAA-compliant platform. Becoming HIPAA-compliant requires a Business Associate Agreement (BAA) with our infrastructure providers, a third-party security audit, specific administrative safeguards, and breach notification procedures. We’re working toward all of those, but we haven’t cleared the bar yet.

What “HIPAA-respectful” means: our Medical Pack — the healthcare vertical of our white-labeled firm portals on WithDave for Firms — is built with HIPAA’s privacy principles in mind, but it is not HIPAA-compliant software and should not be used with protected health information today. Nurse Nadia (the Medical Pack advisor) is prompt-engineered to never echo patient-identifying information back to a patient unless they’ve explicitly shared it. She doesn’t diagnose. She never makes treatment recommendations. Document templates avoid free-text fields where PHI could leak unintentionally.

What this means for early Medical Pack customers: until we have a BAA in place, the Medical Pack is appropriate for use cases that don’t involve protected health information — patient education, appointment prep, generic billing explanations, referral workflows. It is not yet appropriate for clinical decision support, EHR-integrated workflows, or any process that stores PHI. We’ll update this page when that changes.

Questions, or want to be the first BAA partner? Email dave@withdave.ai.

Last updated: April 2026. This page is intentionally honest about where we are. We’d rather under-promise than over-claim.