Legal · Felican AI Inc
HIPAA notice
Effective
Personal-injury case files are full of medical information. This notice explains how InjuryMcGee handles protected health information (“PHI”) and what your firm agrees to when it signs our Business Associate Agreement.
Business Associate Agreement
Felican AI Inc acts as a business associate to the law firms that use InjuryMcGee. Before a firm uploads or connects PHI, a firm owner signs our Business Associate Agreement in the app, under Settings, then Compliance. The signed copy, the version and the date are kept with your workspace and can be downloaded at any time.
Many personal-injury firms receive medical records under a client's authorization and may not be HIPAA covered entities for every purpose. We treat all medical information as PHI either way, and the BAA applies to all of it.
Where PHI is stored and processed
- Storage. Documents and medical records are stored in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's Business Associate Agreement. Storage is private, encrypted at rest, and protected by soft delete and versioning so an accidental deletion or overwrite can be recovered.
- AI and OCR. Reading, classifying, summarizing and drafting run on Microsoft Azure AI Foundry and Azure AI Document Intelligence, in Azure resources owned by Felican AI Inc. Document Intelligence is covered by Microsoft's BAA; the AI models are Anthropic Claude, offered through Azure AI Foundry, and business associate coverage for them is being finalized. Customer data is not used to train models.
- In transit. All traffic uses TLS. Browsers reach files only through short-lived signed links.
Subprocessors
| Subprocessor | Purpose | PHI role |
|---|---|---|
| Microsoft Azure | Blob Storage for documents and medical records; Document Intelligence OCR | Yes, under Microsoft's BAA (Microsoft Product Terms) |
| Anthropic (Claude models via Azure AI Foundry) | AI drafting, summaries and the McGee assistant | Being finalized |
| Hetzner Online | Application hosting | Hosts the application servers |
| Cloudflare | DNS and network edge (TLS, DDoS protection) | Traffic passes through encrypted |
| Resend | Transactional email and approved outbound email | Sends only messages your firm approves |
| Gmail and Google Calendar, only if your firm connects them | Under your firm's own Google Workspace terms |
We will notify workspace owners before adding a subprocessor that handles PHI, and every such subprocessor is bound by terms at least as protective as our BAA.
Safeguards
- Per-firm data isolation and role-based access, so staff see only what their role allows.
- An append-only audit log of access, approvals, sends and exports.
- Minimum-necessary AI requests: each model call receives only the part of the case it needs; Social Security numbers are never sent.
- An approval gate on every outbound message, so PHI leaves the firm only when a person approves the exact content and recipient.
- Secrets kept in server environment files outside code and images; secret scanning before every release.
Breach notification
If we discover a breach of unsecured PHI, we notify the affected firm without unreasonable delay and in any case within the period stated in the BAA, with the information the firm needs to meet its own notification duties.
Questions
Email [email protected]. See also our Privacy Policy and Security page.
Draft pending legal review.