Security & compliance
Built to hold medical records, and honest about where we are.
Personal-injury files are full of PHI. Here is how InjuryMcGee protects them, where they are stored, and how the Business Associate Agreement works.
HIPAA: sign the BAA in the app, then bring real client files
Your firm signs our Business Associate Agreement during setup. PHI files are stored in Microsoft Azure Blob Storage, covered by Microsoft's BAA. AI drafting uses Anthropic Claude through Azure AI Foundry; business associate coverage for the models is being finalized. Read the HIPAA notice.
Controls
What protects your data
- Approval gate on every outbound item
- Agents can draft but cannot send. The sender is a separate service holding the only sending credentials, and it releases an item only after a person approves it, verifying the content hash so what goes out is exactly what was approved. Unapproved items expire after 72 hours.
- Append-only audit log
- Every filing, proposal, approval, rejection, send, export and sign-in is recorded with who, what and when. Entries are hash-chained so a changed or deleted entry is detectable. Firms can export their log.
- Tenant isolation
- Every record carries its firm's ID and every query is scoped to the signed-in user's firm. Isolation is covered by automated tests that run before each release.
- Encryption
- TLS for all traffic to and from the service. Data at rest is encrypted by our storage and database providers. Google connection tokens are additionally encrypted with an application key before they are stored.
- PHI in HIPAA-eligible storage
- Documents, including medical records, live in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's Business Associate Agreement. Storage is private, encrypted at rest, and protected by soft delete and versioning. Files sit under a per-firm prefix and browsers reach them only through short-lived signed links.
- Access and sign-in
- Sign in with Google or email. Roles control who can see ledgers, approve items and export data. Sign-in attempts are rate-limited.
- Untrusted documents stay data
- A fax can contain text that tries to give instructions. Incoming documents are treated as data, agents have narrow tool permissions and no ability to send, and any attempt to add a recipient who is not in the case directory is blocked and flagged.
- Secrets and change control
- Keys live in server environment files outside the code and container images. Code changes go through version control, automated tests and secret scanning before deployment.
Data location
Where your data lives
| What | Where |
|---|---|
| Documents and medical records (PHI) | Microsoft Azure Blob Storage: HIPAA-eligible, covered by Microsoft's BAA, encrypted at rest, soft delete and versioning |
| AI models and OCR | OCR on Azure Document Intelligence (covered by Microsoft's BAA). AI models are Anthropic Claude accessed through Azure AI Foundry in our own Azure resources; business associate coverage for the models is being finalized with our providers, and no customer data is used for training. |
| Application hosting | Dedicated server operated by Hetzner Online |
| DNS and network edge | Cloudflare |
| Transactional email | Resend |
| Gmail and Google Calendar | Google, only if your firm connects it |
The full subprocessor list is in our Privacy Policy. See also our AI use disclosure.
Questions
Security FAQ
Will you sign a Business Associate Agreement?
Yes. Every firm signs our Business Associate Agreement in the app before uploading protected health information. You can read the full text on our BAA page before you sign up.
Where is PHI stored and processed?
Medical files are stored in Microsoft Azure Blob Storage, a HIPAA-eligible service covered by Microsoft's BAA, encrypted at rest with soft delete and versioning. OCR runs on Azure Document Intelligence under the same BAA. AI drafting uses Anthropic Claude models accessed through Azure AI Foundry; business associate coverage for the models is being finalized with our providers.
Do you have SOC 2?
No. We are building to SOC 2 controls and will engage an auditor when the product leaves early access. We will not claim a certification we do not hold.
Is our data used to train AI models?
No. Not ours and not Microsoft's. Requests to models include only the part of the case a task needs, and by default we log token counts, not prompt text.
How do we report a security issue?
Email [email protected] with "Security" in the subject line. We aim to acknowledge reports within two business days.
Start with one case. Keep the queue.
Open the sample firm and approve a records request, or set up your own workspace in a few minutes. Your firm signs our BAA in the app before any client records go in.