Trust & security

How Atticus protects health information.

Atticus runs on AWS with layered safeguards for health information, clinical operations, and customer review.

Last updated: August 24, 2026

AWSBusiness Associate Addendum executed
AES-256Encryption at rest
TLS 1.2+Encryption in transit
ContinuousSecurity monitoring

Our approach

Built for trust from the first record.

Atticus limits access to health information, protects it with encryption, and records clinical access for review.

Atticus is a HIPAA covered health care provider for care delivered under its own provider NPI, including electronic eligibility transactions. Atticus also acts as a HIPAA Business Associate for delegated customer work. Our safeguards apply across both roles.

AWS security foundation

AWS is the foundation.

Atticus runs on Amazon Web Services under an executed AWS Business Associate Addendum. We use HIPAA-eligible AWS services within its scope.

01

Protect the data

AES-256 and AWS KMS protect data at rest. TLS 1.2 or higher protects data in transit.

02

Control access

Named identities, MFA, scoped roles, and regular reviews enforce least-privilege access.

03

Monitor continuously

Amazon GuardDuty and AWS Security Hub support continuous detection, review, and response.

04

Protect every entry point

AWS WAF and layered application controls protect public services from common attack patterns.

Data protection

Health information stays within approved boundaries.

01

Approved storage

Health information stays in approved encrypted systems with defined access controls.

02

Limited exposure

Atticus limits the movement and visibility of health information across services.

03

Minimum necessary access

Services request the fields required for a defined task. Authorization and consent checks apply at clinical boundaries.

04

Reviewable activity

Clinical access and changes create retained evidence for investigation and customer review.

AI safety guardrails

Bounded agents. Human clinical authority.

AI can support care work. It does not replace clinical judgment or identity safety.

01

No prescribing

Agents do not recommend specific medications or dosages. Clinical decisions remain with clinicians.

02

Identity confidence

Uncertain identity matches do not trigger automatic care actions. A wrong-patient match is a safety event.

03

Controlled model context

Models receive de-identified content or controlled references. Raw member records do not enter general prompts.

04

Recorded decisions

Agent decisions, approved actions, and outcomes create reviewable evidence under the same audit controls.

Vulnerability management

Security checks start before release.

Automated security checks, peer review, dependency review, and release controls apply before production changes.

Responsible disclosure

Tell us when something looks wrong.

Email hello@atticushealth.com with steps that help us reproduce the issue. We acknowledge good-faith reports and provide investigation updates.

Security review

Bring your questionnaire.

Qualified customers can request security documents, control evidence, and a guided architecture review.

Request a security review