Security and data handling

Updated September 25, 2026

Status: Practice demos are open. CHAI runs daily on its founder’s record, and we’re preparing our first practice deployments.

Our approach: CHAI uses a dedicated server for each practice, private-network access, encryption and a record of changes. Patient data is never sold or used to train AI models. The sections below distinguish current controls from work planned before practice launch.

Where CHAI runs

Who can see what

Services that process patient data

How CHAI makes answers reviewable

Approvals

CHAI proposes dose and protocol changes, with the calculation behind each one. Only a clinician or practice-admin account can accept one; nothing is applied until they do, and the acceptance is recorded with who accepted it and when. Patient accounts cannot accept dose or protocol changes. Checkpoint rules flag a result; they don't change a dose on their own. A signed clinician review record, with dual-review badges and document upload, is in development.

HIPAA

CHAI is built to the HIPAA Security Rule. We don't call it "HIPAA compliant" until the pieces below are in place for your practice.

In progress before launch

Questions

Security and procurement questions go to sales@centurionhealth.ai. We can walk through current controls, deployment plans and outstanding requirements for your practice. For how this website handles your information, see the privacy policy.