Our approach
Built for trust from the first record.
Atticus limits access to health information, protects it with encryption, and records clinical access for review.
Atticus is a HIPAA covered health care provider for care delivered under its own provider NPI, including electronic eligibility transactions. Atticus also acts as a HIPAA Business Associate for delegated customer work. Our safeguards apply across both roles.
AWS security foundation
AWS is the foundation.
Atticus runs on Amazon Web Services under an executed AWS Business Associate Addendum. We use HIPAA-eligible AWS services within its scope.
Protect the data
AES-256 and AWS KMS protect data at rest. TLS 1.2 or higher protects data in transit.
Control access
Named identities, MFA, scoped roles, and regular reviews enforce least-privilege access.
Monitor continuously
Amazon GuardDuty and AWS Security Hub support continuous detection, review, and response.
Protect every entry point
AWS WAF and layered application controls protect public services from common attack patterns.
Data protection
Health information stays within approved boundaries.
Approved storage
Health information stays in approved encrypted systems with defined access controls.
Limited exposure
Atticus limits the movement and visibility of health information across services.
Minimum necessary access
Services request the fields required for a defined task. Authorization and consent checks apply at clinical boundaries.
Reviewable activity
Clinical access and changes create retained evidence for investigation and customer review.
AI safety guardrails
Bounded agents. Human clinical authority.
AI can support care work. It does not replace clinical judgment or identity safety.
No prescribing
Agents do not recommend specific medications or dosages. Clinical decisions remain with clinicians.
Identity confidence
Uncertain identity matches do not trigger automatic care actions. A wrong-patient match is a safety event.
Controlled model context
Models receive de-identified content or controlled references. Raw member records do not enter general prompts.
Recorded decisions
Agent decisions, approved actions, and outcomes create reviewable evidence under the same audit controls.
Vulnerability management
Security checks start before release.
Automated security checks, peer review, dependency review, and release controls apply before production changes.
Responsible disclosure
Tell us when something looks wrong.
Email hello@atticushealth.com with steps that help us reproduce the issue. We acknowledge good-faith reports and provide investigation updates.
Security review
Bring your questionnaire.
Qualified customers can request security documents, control evidence, and a guided architecture review.