How Snapback Health uses, monitors, and constrains artificial intelligence within our remote therapeutic monitoring platform. This document is intended for healthcare partners, clinic compliance officers, and regulators.
Artificial intelligence in our platform is an assistive tool. AI does not make autonomous clinical decisions, modify clinical records without confirmation, or replace the judgment of licensed providers. Every AI-suggested data entry requires the patient to review and confirm before it is saved.
AI in Snapback Health is used for patient education, data capture assistance, and routine triage. It is not a diagnostic tool. Wound assessment AI explicitly states it is not a medical diagnosis and instructs patients to contact their care team for any concerns.
Every AI interaction is logged with timestamp, user identifier, input context, output content, and patient confirmation status. Logs are retained for clinical and compliance review.
For any clinical concern, abnormal finding, or patient question outside routine recovery education, the AI directs the patient to contact their clinical care team. The AI is configured to be conservative rather than confident when clinical risk is present.
Snapback Health uses AI in the following defined ways:
Patient health information transmitted to or processed by AI is governed by our Privacy Policy and Business Associate Agreement framework. Our data infrastructure runs on HIPAA-eligible cloud services under signed Business Associate Agreements where applicable.
| Category | Approach |
|---|---|
| AI inference | Claude models. Protected health information is removed at the application boundary before any inference call. Migration to Amazon Bedrock — Claude hosted within our AWS account under the AWS Business Associate Agreement — is in progress to bring inference fully inside the HIPAA compliance perimeter. |
| Data retention by AI vendors | Zero data retention configuration is our target architecture. AI providers do not train on Snapback Health patient data. |
| Encryption | TLS 1.2+ in transit. Encryption at rest at the database layer. |
| Audit logging | All AI interactions logged to immutable audit trail with patient consent and confirmation status. |
| Cloud infrastructure | HIPAA-eligible AWS services under the AWS Business Associate Agreement (executed May 30, 2026; account designated as a HIPAA Account). |
Snapback Health is a clinician-led platform. Clinical content — procedure protocols, exercise plans, recovery timelines, red flag criteria — is reviewed and approved by qualified clinical personnel before deployment. AI output is grounded in this clinician-approved content.
Providers retain full authority over their patients' care. The platform supports clinical decision-making; it does not substitute for it.
If an AI output contributes to or fails to identify a clinical concern, we take the following steps:
Care teams and patients can report concerns about AI behavior to our privacy team at any time.
Patients are informed in plain language that:
Snapback Health's approach is informed by the following frameworks and standards:
Formal certifications such as SOC 2 Type II and HITRUST alignment are on our roadmap as the platform matures and patient volume grows.
We are committed to continuous improvement of our AI governance. Near-term priorities include:
We welcome dialogue with clinics, partners, regulators, and patients on responsible AI in healthcare.
Privacy and compliance contact:
privacy@snapbackhealth.com
General inquiries:
john.oshea@snapbackhealth.com
Snapback Health Technologies LLC
210 West Cedar Avenue, Flagstaff, AZ 86001