Skip to content

Security & compliance

Built to hold medical records, and honest about where we are.

Personal-injury files are full of PHI. Here is how InjuryMcGee protects them, where they are stored, and how the Business Associate Agreement works.

HIPAA: sign the BAA in the app, then bring real client files

Your firm signs our Business Associate Agreement during setup. PHI files are stored in Microsoft Azure Blob Storage, covered by Microsoft's BAA. AI drafting uses Anthropic Claude through Azure AI Foundry; business associate coverage for the models is being finalized. Read the HIPAA notice.

Controls

What protects your data

Approval gate on every outbound item
Agents can draft but cannot send. The sender is a separate service holding the only sending credentials, and it releases an item only after a person approves it, verifying the content hash so what goes out is exactly what was approved. Unapproved items expire after 72 hours.
Append-only audit log
Every filing, proposal, approval, rejection, send, export and sign-in is recorded with who, what and when. Entries are hash-chained so a changed or deleted entry is detectable. Firms can export their log.
Tenant isolation
Every record carries its firm's ID and every query is scoped to the signed-in user's firm. Isolation is covered by automated tests that run before each release.
Encryption
TLS for all traffic to and from the service. Data at rest is encrypted by our storage and database providers. Google connection tokens are additionally encrypted with an application key before they are stored.
PHI in HIPAA-eligible storage
Documents, including medical records, live in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's Business Associate Agreement. Storage is private, encrypted at rest, and protected by soft delete and versioning. Files sit under a per-firm prefix and browsers reach them only through short-lived signed links.
Access and sign-in
Sign in with Google or email. Roles control who can see ledgers, approve items and export data. Sign-in attempts are rate-limited.
Untrusted documents stay data
A fax can contain text that tries to give instructions. Incoming documents are treated as data, agents have narrow tool permissions and no ability to send, and any attempt to add a recipient who is not in the case directory is blocked and flagged.
Secrets and change control
Keys live in server environment files outside the code and container images. Code changes go through version control, automated tests and secret scanning before deployment.
injurymcgee.com/app/approvals
Approvals queue with a policy-limits demand open for attorney review, showing the pre-send checks and the approve, edit and reject buttons. Sample firm, fictional clients.

Data location

Where your data lives

Where InjuryMcGee stores and processes data
WhatWhere
Documents and medical records (PHI)Microsoft Azure Blob Storage: HIPAA-eligible, covered by Microsoft's BAA, encrypted at rest, soft delete and versioning
AI models and OCROCR on Azure Document Intelligence (covered by Microsoft's BAA). AI models are Anthropic Claude accessed through Azure AI Foundry in our own Azure resources; business associate coverage for the models is being finalized with our providers, and no customer data is used for training.
Application hostingDedicated server operated by Hetzner Online
DNS and network edgeCloudflare
Transactional emailResend
Gmail and Google CalendarGoogle, only if your firm connects it

The full subprocessor list is in our Privacy Policy. See also our AI use disclosure.

Questions

Security FAQ

Will you sign a Business Associate Agreement?

Yes. Every firm signs our Business Associate Agreement in the app before uploading protected health information. You can read the full text on our BAA page before you sign up.

Where is PHI stored and processed?

Medical files are stored in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's BAA, encrypted at rest with soft delete and versioning. OCR runs on Azure Document Intelligence under the same BAA. AI drafting uses Anthropic Claude models accessed through Azure AI Foundry; business associate coverage for the models is being finalized with our providers.

Do you have SOC 2?

No. We are building to SOC 2 controls and will engage an auditor when the product leaves early access. We will not claim a certification we do not hold.

Is our data used to train AI models?

No. Not ours and not Microsoft's. Requests to models include only the part of the case a task needs, and by default we log token counts, not prompt text.

How do we report a security issue?

Email [email protected] with "Security" in the subject line. We aim to acknowledge reports within two business days.

Start with one case. Keep the queue.

Open the sample firm and approve a records request, or set up your own workspace in a few minutes. Your firm signs our BAA in the app before any client records go in.

Security & compliance · InjuryMcGee — Powered by Felican.ai