Security and compliance

Built for your security review, and honest about where we are.

Healthcare buyers worry that a new document tool will stall in privacy review. InfoNotData is designed around the requirements your reviewers check, and this page says plainly what’s built, what’s in progress, and what to ask us.

  • Extraction only, no generated text
  • Built for HIPAA and VA Handbook 6500
  • Built for the RMF and ATO process

01 / Design principles

Security starts with what the system refuses to do.

Extraction only

InfoNotData never generates text about a patient. It extracts specific values and cites their source, so what it produces is small, checkable, and traceable.

People review uncertainty

Low-confidence pages go to a person on your team. The system doesn’t guess, so errors don’t hide inside an automated result.

Nothing upstream changes

Your fax numbers, fax server, and EHR stay as they are. InfoNotData doesn’t integrate directly with EHRs today.

02 / Frameworks

What InfoNotData is built for.

These are the frameworks your reviewers will ask about. We use “built for” deliberately: it describes design intent, not a certificate.

Privacy

HIPAA

Designed for the HIPAA Privacy and Security Rules that govern protected health information in faxed records.

Encryption

FIPS-validated encryption

Built to use FIPS-validated cryptography, as federal and many hospital security reviews require.

VA

VA Handbook 6500 and IRB protocols

Built for the VA’s information security program requirements and for research review where a pilot calls for it.

Federal

Risk Management Framework and ATO

Built for the RMF and Authority to Operate process. InfoNotData does not currently hold an ATO. Ask us for current status.

“Built for” means designed to meet these requirements. It is not a certification. There is no official “HIPAA certification,” and we don’t claim one.

03 / Your review

Bring your vendor-risk questionnaire.

Every health system and federal program has its own review. The fastest path is to bring your questionnaire, or your security team, to the walkthrough and go through it with an engineer. We’ll answer what we can on the spot and tell you plainly what’s still in progress.

This website follows the same care: the demo request form asks for business contact details only and warns against including patient information. See our privacy policy and accessibility statement.

Security questions

What reviewers ask first.

Is InfoNotData HIPAA certified?

There is no official HIPAA certification, for any vendor. InfoNotData is built for HIPAA requirements, and we’ll walk your team through how.

Does InfoNotData have a federal Authority to Operate?

Not currently. It is built for the Risk Management Framework and ATO process. Ask us for current status.

Does it generate text about patients?

No. It is extraction-only. It pulls specific values and cites the page and line each came from.

Does it connect to our EHR?

Not directly, today. It works on documents as they arrive, so nothing in your EHR changes.

Can we send patient information through the website form?

Please don’t. The demo request form is for business contact details only.

06 / Next step

Review it with an engineer.

A 30-minute walkthrough. Bring your vendor-risk questionnaire or your security team, and we’ll go through it together.

What happens next

  1. An engineer replies to set a time that works for your team.
  2. A 30-minute walkthrough on a synthetic or de-identified packet.
  3. If it fits, we scope a pilot on your own queue.

An engineer, not a sales script. We’ll show you what it doesn’t do, too.

Tampa, Florida
Where do your faxes land?
Organization type
Pages a month. A rough estimate is fine.
Who should we talk to?
Anything we should prepare?
For example: your specialty, your EHR, or your security review timeline.

Business contact details only. Please don’t include any patient information.