Symmetry Your Behind-The-Scenes Partner

Compliance as architecture

HIPAA compliance you can demonstrate rather than assert - because an audit trail written after the fact is a story, and one written by the system is a record.

There are two ways to arrive at HIPAA compliance. One is to build the system you wanted and then document your way to defensibility. The other is to make the compliant path the only path the software knows how to take.

We build the second kind, and the difference shows up on the day someone asks a question the paperwork cannot answer.

Every disclosure, audited twice

When a chart is accessed inside a Symmetry Practice practice, two independent records are written.

PracticeHI logs the access in its own audit tables before a byte moves. Symmetry writes its own tamper-evident access trail: who looked, at whose record, from which surface. Neither depends on the other being correct, and neither can be quietly amended after the fact.

Two trails from two systems is not redundancy for its own sake. It means the answer to “who saw this patient’s record, and when” does not rest on a single component behaving honestly.

Accounting of disclosures, per patient

A patient has the right to ask what happened to their information. Answering that well means the accounting has to exist per patient rather than as a query someone reconstructs across logs under time pressure.

So it is kept that way from the start. The disclosure history for an individual is a first-class record, not a report assembled on demand.

Minimization on a schedule

Sensitive content does not accumulate indefinitely because nobody got around to deciding. It is minimized on a retention schedule - the system’s default is to hold less over time, and keeping more is the decision that requires justification.

Storage is cheap; retained PHI is not. The cost of holding a record you no longer need is not measured in gigabytes.

The same standard for our AI as for any person

This is where a lot of otherwise careful platforms quietly make an exception, so let us be explicit about not making one.

AI processing runs under business associate agreements. Every tool an AI touches lands in the same auditable record as any human action. A model reading a chart is a disclosure, logged exactly as a person reading that chart is logged - because from the patient’s perspective there is no meaningful difference, and the regulation does not offer a discount for automation.

Per-client budget ceilings bound what the automation can do. The audit trail records what it did.

Why architecture rather than policy

Policy describes what people should do. Architecture determines what the system permits.

Both matter, but only one of them holds at three in the morning when an integration misbehaves, or a year later when the person who wrote the policy has moved on. Compliance built into behavior does not depend on anyone remembering it - which is the only kind worth promising a practice.

← All posts

Want this running around your business?

A discovery call is the fastest way to find out which parts of your back office should become ours.

Book a Discovery Call

Book a discovery call