Mallowa handles Protected Health Information on behalf of individuals and families coordinating disability and developmental care. When a clinic, agency, or provider organization uses Mallowa, that organization is a HIPAA Covered Entity and Mallowa is its Business Associate. This page describes what that means in practice — the agreement we sign, the subprocessors we use, the rights individuals have, and how we handle breaches if they occur.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) governs how Protected Health Information (PHI) is used, disclosed, and safeguarded. It creates two categories of regulated parties:
When a clinic, hospital, ABA agency, OT/SLP practice, or school health team uses Mallowa to coordinate care for the individuals they serve, that organization is a Covered Entity and Mallowa is its Business Associate. Mallowa enters into a Business Associate Agreement with the organization formalizing the relationship.
When an individual or family uses Mallowa directly to coordinate care for themselves or a loved one, they are not themselves a Covered Entity (HIPAA does not regulate individuals managing their own or their child's care). The same technical and operational protections still apply — but the BAA framework is mechanically a Covered-Entity-to-Business-Associate contract and doesn't fit the direct-use case.
When Mallowa handles PHI on behalf of a Covered Entity, we commit to:
Our standard Business Associate Agreement is mapped clause-by-clause to every provision HIPAA requires (45 C.F.R. §164.504(e)(2)(ii), §164.314(a), §164.410) and is provided to Covered Entities at the time of subscription or on request. Independent health-law counsel review is not yet complete. The agreement covers:
Requesting the BAA. If you're a Covered Entity evaluating Mallowa for your organization, email hello@mallowa.com with “BAA Request” in the subject and we'll send the current version. Providers signing up online execute the agreement in-product during onboarding.
Mallowa uses a small number of infrastructure providers to deliver the service. Each handles PHI only to the extent required for the service it provides, and each is bound by a Business Associate Agreement (or equivalent contractual protection).
| Provider | Role | Hosting region |
|---|---|---|
| Convex | Database, server runtime, file storage, real-time sync | United States |
| Vercel | Application hosting, serverless functions, edge network | United States |
| Paubox | HIPAA-compliant transactional email delivery (notifications, password reset, invites), under Paubox's BAA covering the send leg. Most templates carry no PHI; appointment reminders and questionnaire invitations do — see Minimum necessary standard below. | United States |
| Anthropic (Claude) | AI inference for de-identified pattern analysis (Growth tier only) | United States |
| Amazon Web Services | Document OCR (Textract), clinical dictation transcription (Transcribe Medical), and telehealth video (Chime) — HIPAA-eligible services under the AWS BAA | United States |
| Stripe | Subscription billing and payment processing (no PHI) | United States |
| Sentry | Error monitoring (PHI-scrubbed before transmission) | United States |
We'll notify Covered Entity customers at least 30 days before adding a new subprocessor that will have access to PHI, giving you the opportunity to object (and, if we can't address the objection, to terminate without penalty).
HIPAA Safe Harbor de-identification (45 CFR §164.514(b)) lists 18 categories of identifiers that, when removed, render data sufficiently de-identified that it is no longer considered PHI. Mallowa's 7-layer de-identification pipeline is built around this list:
The pipeline strips these categories from data before AI inference. Where dates are needed for clinical reasoning, we replace them with age-bucket categoricals (e.g., “school-age, <13”) rather than the actual date. The full pipeline implementation is open in discussion with auditors under NDA.
Individuals whose PHI is held in Mallowa have rights under the HIPAA Privacy Rule. Mallowa supports these rights as follows:
Individuals (or their personal representatives) can view everything Mallowa holds about them, organized by record type. This is available in-app for the account owner of the individual's record; family-role members can also view via their dashboard. For requests outside the app (paper copy, alternate format), email hello@mallowa.com and we'll respond within the 30-day window required by §164.524(b)(2).
Most records in Mallowa are user-editable directly. For records that aren't (audit-log entries are immutable by design — they're the system of record for who did what when), an amendment request can append context to the record without modifying the original entry, preserving the audit trail. Email hello@mallowa.com with details.
Individuals have the right to an accounting of certain disclosures of their PHI made in the prior six years. Family-role members can view a derived disclosure log in-app showing actor, role, action, resource type, and timestamp. The audit log is retained for the full six-year period required by the rule.
Mallowa's visibility controls (Team / Clinical only / Family only / Author only / Custom) let care team members restrict who sees specific notes. For broader restrictions — limiting which providers see what, restricting disclosures to particular individuals — email hello@mallowa.com.
Mallowa supports per-user notification preferences (push, email, in-app) and per-user contact information (alternate phone, alternate email). Configurable from Settings → Notifications.
HIPAA's minimum necessary standard (45 CFR §164.502(b)) requires that PHI use, disclosure, or request be limited to the minimum necessary to accomplish the intended purpose. Mallowa is built around this:
Two notification types are a deliberate, narrow exception, and exist because the reminder would not function without them. Appointment-reminder emails name the individual, the appointment type, the provider, and the location (or telehealth link) — both in the subject and the body. Questionnaire-invitation emails name the sender and the clinical instrument in the subject (the instrument name can itself be clinically revealing) and may include a free-text cover note the sender writes. Every transactional email — including these two — sends through Paubox under Paubox's HIPAA Business Associate Agreement, which covers encryption and an audit trail on the send leg. That BAA does not extend past delivery: the recipient's own mail provider and inbox are outside it, so sending PHI by email relies on the recipient having consented to receive it that way (see Confidential Communications above for how to change a recipient's notification channel).
A breach under HIPAA §164.402 is the acquisition, access, use, or disclosure of unsecured PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI.
If we discover or are notified of a security incident affecting Mallowa that constitutes a breach, we will:
Breach notifications include: a brief description of what happened, the types of PHI involved, steps the individual should take to protect themselves, what we're doing to investigate and prevent recurrence, and contact information.
HIPAA Privacy Officer. Skyler Kruger (Founder, Trellis Care Coordination LLC) — currently serves as the designated Privacy Officer responsible for development and implementation of Mallowa's privacy policies and procedures.
HIPAA Security Officer. Skyler Kruger (Founder, Trellis Care Coordination LLC) — currently serves as the designated Security Officer responsible for development and implementation of security policies and procedures.
Contact: compliance@mallowa.com
(As Mallowa grows, these roles will be assigned to dedicated personnel and updated on this page.)
If you believe Mallowa has violated your HIPAA rights, you have several options:
Mallowa will not retaliate against you for filing a complaint.