Overview
Vivy, Inc. ("Vivy") is building administrative, physical, and technical safeguards intended to support HIPAA-aligned handling of health information in applicable workflows.
Whether Vivy acts as a Business Associate depends on the customer, workflow, services in use, and completed contractual agreements. Covered entities should confirm that the required agreement and configuration are in place before sharing Protected Health Information (PHI).
What constitutes PHI on Vivy
Protected Health Information (PHI) on Vivy may include: biomarker measurements, protocol logs, medication and supplement records, health goals, and any other individually identifiable health information you enter into the app.
PHI is stored under your authenticated user ID in Firebase Firestore and is governed by our Firestore security rules, which enforce strict user-level isolation.
Use and disclosure of PHI
Permitted uses. We use health information to provide the Vivy service — including protocol tracking, contextual insights, and biomarker analysis — and as otherwise permitted by applicable agreements and law.
No sale of PHI. We do not sell, rent, or otherwise monetize PHI.
Minimum necessary. We apply the HIPAA minimum necessary standard, limiting access to PHI to what is required to perform a specific function.
AI processing. AI requests are routed through controlled server-side services with authorization, data-use, and audit controls. Organizations handling regulated data should confirm the applicable service configuration and contractual coverage before enabling a covered workflow.
Your rights as a patient
Under HIPAA, you have the right to access your PHI, request corrections, receive an accounting of disclosures, and request restrictions on use.
To exercise any HIPAA right, contact our Privacy Officer at support@heyvivy.com. We will respond within the timeframes required by HIPAA (generally 30 days, with one possible 30-day extension).
You may also delete your account and all associated PHI at any time through the app (Settings → Account → Delete Account).
Breach notification
In the event of a breach of unsecured PHI, we will notify affected individuals, the Secretary of the U.S. Department of Health and Human Services (HHS), and, where applicable, the media — within the timeframes required by the HIPAA Breach Notification Rule.
We maintain an incident response plan that is reviewed and tested annually. Our team is trained to identify and escalate potential breaches immediately.
Business Associate Agreements
Business Associate Agreement availability depends on the organization, intended workflow, service configuration, and completion of contractual review. A BAA should be fully executed before a covered entity uses Vivy for a workflow that requires one.
To discuss contractual requirements for a proposed covered workflow, contact support@heyvivy.com.
Complaints
If you believe your HIPAA rights have been violated, you may file a complaint with our Privacy Officer at support@heyvivy.com or directly with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/ocr.
We will not retaliate against any individual for filing a good-faith complaint.
Security safeguards
How we protect your data
Administrative safeguards
- Designated HIPAA Security Officer
- Workforce training on PHI handling policies
- Access controls and minimum necessary standard
- Vendor agreements and data-processing terms reviewed for covered workflows
- Incident response and breach notification procedures
- Regular risk assessments and policy reviews
Physical safeguards
- All PHI stored in Google Cloud infrastructure (Firebase), which maintains SOC 2 Type II and ISO 27001 certifications
- No on-premises servers; no physical access to infrastructure by Vivy employees
- Workstation access controls and device management policies for team members
Technical safeguards
- Encryption in transit and platform-managed encryption at rest
- Firestore security rules enforce per-user data isolation
- Firebase Authentication with secure token management
- Audit logging of all PHI access events
- Automatic session expiration and re-authentication requirements
- Role-based access controls limiting internal access to PHI