Hey Vivy
PricingPractitioners
Sign inGet the app↗
Get the app
Trust / HIPAADocument 03

Health information

HIPAA & health data

Effective date: March 1, 2026 · Last updated: March 1, 2026

Vivy takes the privacy and security of health information seriously. This page describes safeguards designed to support HIPAA-aligned handling of health information and the agreements covered workflows require.

HIPAA-aligned controlsContract review requiredSOC 2-alignedEncryption at restAudited access

On this page

  1. 01Overview
  2. 02What constitutes PHI on Vivy
  3. 03Use and disclosure of PHI
  4. 04Your rights as a patient
  5. 05Breach notification
  6. 06Business Associate Agreements
  7. 07Complaints
  8. 08Security safeguards
01

Overview

Vivy, Inc. ("Vivy") is building administrative, physical, and technical safeguards intended to support HIPAA-aligned handling of health information in applicable workflows.

Whether Vivy acts as a Business Associate depends on the customer, workflow, services in use, and completed contractual agreements. Covered entities should confirm that the required agreement and configuration are in place before sharing Protected Health Information (PHI).

02

What constitutes PHI on Vivy

Protected Health Information (PHI) on Vivy may include: biomarker measurements, protocol logs, medication and supplement records, health goals, and any other individually identifiable health information you enter into the app.

PHI is stored under your authenticated user ID in Firebase Firestore and is governed by our Firestore security rules, which enforce strict user-level isolation.

03

Use and disclosure of PHI

Permitted uses. We use health information to provide the Vivy service — including protocol tracking, contextual insights, and biomarker analysis — and as otherwise permitted by applicable agreements and law.

No sale of PHI. We do not sell, rent, or otherwise monetize PHI.

Minimum necessary. We apply the HIPAA minimum necessary standard, limiting access to PHI to what is required to perform a specific function.

AI processing. AI requests are routed through controlled server-side services with authorization, data-use, and audit controls. Organizations handling regulated data should confirm the applicable service configuration and contractual coverage before enabling a covered workflow.

04

Your rights as a patient

Under HIPAA, you have the right to access your PHI, request corrections, receive an accounting of disclosures, and request restrictions on use.

To exercise any HIPAA right, contact our Privacy Officer at support@heyvivy.com. We will respond within the timeframes required by HIPAA (generally 30 days, with one possible 30-day extension).

You may also delete your account and all associated PHI at any time through the app (Settings → Account → Delete Account).

05

Breach notification

In the event of a breach of unsecured PHI, we will notify affected individuals, the Secretary of the U.S. Department of Health and Human Services (HHS), and, where applicable, the media — within the timeframes required by the HIPAA Breach Notification Rule.

We maintain an incident response plan that is reviewed and tested annually. Our team is trained to identify and escalate potential breaches immediately.

06

Business Associate Agreements

Business Associate Agreement availability depends on the organization, intended workflow, service configuration, and completion of contractual review. A BAA should be fully executed before a covered entity uses Vivy for a workflow that requires one.

To discuss contractual requirements for a proposed covered workflow, contact support@heyvivy.com.

07

Complaints

If you believe your HIPAA rights have been violated, you may file a complaint with our Privacy Officer at support@heyvivy.com or directly with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr.

We will not retaliate against any individual for filing a good-faith complaint.

08

Security safeguards

How we protect your data

Administrative safeguards

  • ✓Designated HIPAA Security Officer
  • ✓Workforce training on PHI handling policies
  • ✓Access controls and minimum necessary standard
  • ✓Vendor agreements and data-processing terms reviewed for covered workflows
  • ✓Incident response and breach notification procedures
  • ✓Regular risk assessments and policy reviews

Physical safeguards

  • ✓All PHI stored in Google Cloud infrastructure (Firebase), which maintains SOC 2 Type II and ISO 27001 certifications
  • ✓No on-premises servers; no physical access to infrastructure by Vivy employees
  • ✓Workstation access controls and device management policies for team members

Technical safeguards

  • ✓Encryption in transit and platform-managed encryption at rest
  • ✓Firestore security rules enforce per-user data isolation
  • ✓Firebase Authentication with secure token management
  • ✓Audit logging of all PHI access events
  • ✓Automatic session expiration and re-authentication requirements
  • ✓Role-based access controls limiting internal access to PHI
Business Associate Agreement

Need a Business Associate Agreement?

Covered entities evaluating a workflow that requires a BAA can contact us to discuss requirements, service configuration, and the current contractual review status.

Contact compliance →
Hey Vivy

One routine is enough to begin.

Create an account, add what you're already doing, and let your history become more useful over time.

Hey Vivy for mobile

Free to start on iPhoneGet Hey Vivy→

Google Play coming soon.

Product

  • Overview
  • Intelligence
  • Tracking
  • Compound library
  • Pricing

Use cases

  • Longevity
  • GLP-1 tracking
  • Peptide tracking
  • Vivy Pro

Resources

  • Tools
  • Blog
  • Score methodology
  • FAQ

Company

  • About
  • Careers
  • Contact & support

© 2026 Hey Vivy, Inc.

PrivacyTermsAI disclaimerHIPAASign in

Vivy provides informational insights, not medical advice. It does not diagnose, prescribe, or replace a qualified healthcare provider.