Compliance

HIPAA posture

LeanDoze is being prepared for clinic use with identifiable patient data, but clinics should review compliance requirements before production use.

Last updated: August 2, 2026

LeanDoze is a tracking and support tool. It does not provide medical diagnosis, treatment, or prescribing advice. Always consult your healthcare provider for medical questions.

Current posture

LeanDoze is a health-adjacent tracking and support platform. When clinics use LeanDoze with identifiable patient information, HIPAA and related privacy obligations may apply.

Before clinics rely on LeanDoze for protected health information, LeanDoze should complete a formal HIPAA readiness review, security policies, incident response procedures, access controls, audit logging, vendor review, and Business Associate Agreement workflow.

Clinic responsibility

Clinics are responsible for determining whether their LeanDoze usage involves protected health information and whether a Business Associate Agreement or additional safeguards are required.

LeanDoze should not be presented as HIPAA-compliant for clinic PHI workflows until the required legal, technical, and contractual controls are completed.

Security direction

LeanDoze should use least-privilege access, authenticated patient consent, encrypted production databases, secure environment variables, audit trails, and role-based clinic access.

Patients should always own their profile and clinics should only access patients after explicit PatientAccess exists.

BAA readiness checklist

Before clinic commercialization, confirm BAAs and compliance posture for hosting, authentication, database, billing, email, analytics, and any support tooling that may touch identifiable health information.

Document data retention, deletion, breach notification, employee access, backups, logging, and support procedures.

Questions or data requests

For privacy, export, deletion, or compliance requests, contact LeanDoze support. We will verify the request before taking action.

Contact support