How we protect patient information, who we share it with, and where we are on independent validation.
Last updated 16 August 2026
Lillia is built around health-data privacy from the ground up. Patient information is encrypted, access-controlled and audited; client data is hosted in the region agreed with each client; and we sign a data processing agreement — including a HIPAA Business Associate Agreement where US law applies — before any patient data moves. Our independent validation programme is underway and dated below.
Live control status and documentsOur Trust Center shows the current state of our security controls, monitored continuously, and lets you request documentation directly.
Client data is hosted and processed in the region agreed with each client — currently the United States and Qatar. Deployments are region-specific, so data stays in its agreed region.
Encryption
Patient information is encrypted in transit and at rest.
Access control
Role-based access with least privilege, and multi-factor authentication enforced for access to systems handling patient information.
Auditability
Clinical and administrative actions are recorded in an audit trail.
Continuous monitoring
Our control environment is monitored continuously through Sprinto — a living programme rather than a point-in-time exercise.
Testing
Vulnerability scanning and internal penetration testing run on an ongoing basis, with an independent third-party test scheduled.
Our privacy and security programme
A formal security programme with a documented risk assessment, maintained and monitored continuously.
Written policies covering security, privacy, access management and secure development.
A documented incident response plan and breach notification procedure.
Workforce security training and role-appropriate access review.
A data processing agreement executed before any patient information is exchanged — without exception.
A maintained sub-processor register, with agreements in place for every vendor in the patient-data path.
Regional legal frameworks
Our agreements are structured as a single data processing agreement with the annex that applies to your jurisdiction.
United States
HIPAA and the HITECH Act. We execute a Business Associate Agreement containing the provisions required by 45 CFR §164.504(e), and we hold a HIPAA Business Associate Agreement with our cloud provider.
State of Qatar
Law No. 13 of 2016 on Personal Data Privacy Protection. We act as a processor on the controller's instructions, with data held in-region and additional protection for health data.
Our data processing agreementRead our standard agreement, including the HIPAA Business Associate Agreement for US clients, before you request it. We are equally happy to work from your paper.
We are an AI platform, so we think this deserves a direct answer rather than a footnote.
Patient data is never used to train or improve AI models. Not ours, and not any provider's.
Our primary AI processing runs inside Google Cloud, in your agreed hosting region, under an executed data protection agreement with Google that includes HIPAA business associate terms.
Where a limited category of interactions is processed by an additional AI provider, that provider is also covered by a signed Business Associate Agreement.
Every AI provider in the patient-data path appears in our sub-processor register, which we share with clients under NDA.
Clinical judgment stays with clinicians. Lillia supports care teams; it does not replace them, and clinical escalations involve a human.
Independent validation
We believe in saying plainly what is complete and what is scheduled.
In place
HIPAA security programme with continuous control monitoring
Documented risk assessment, policies, incident response and evidence maintained in Sprinto.
In place
Business Associate Agreements across the data path
Executed with our cloud and AI providers, and with every client before patient data moves.
October 2026
External HIPAA attestation
Independent examination performed by a CPA firm.
October 2026
Independent penetration test
Third-party assessment, with an attestation letter available to clients afterwards.
November 2026
SOC 2 Type II audit
Audit fieldwork in late November, following a three-month control observation period.
December 2026
SOC 2 Type II report issued
Available to clients and prospective clients under NDA once issued.
Working with us
Data processing agreement
We sign a data processing agreement before any patient information is exchanged — with a HIPAA Business Associate Agreement annexed where US law applies, and the equivalent annex for Qatar. We are happy to use our template or yours.
Security questionnaires
We complete client and network vendor security assessments, including standard formats. We acknowledge within one business day and return completed assessments within ten business days.
Documentation available under NDA
Our security overview, HIPAA control mapping, architecture and data-flow documentation, sub-processor register and — as each is issued — our attestation letters and SOC 2 report. Requests can be made through our Trust Center.
Reporting a security concern
If you believe you have found a security issue affecting Lillia, please contact us at security@lilliacare.ai. We investigate every report and will acknowledge receipt.
Request our security documentation
See our live control status and request documents through the Trust Center, or tell us what your review needs and we will send the relevant material under NDA — usually within one business day.