Snapback Health

AI Governance

How Snapback Health uses, monitors, and constrains artificial intelligence within our remote therapeutic monitoring platform. This document is intended for healthcare partners, clinic compliance officers, and regulators.

Version 1.1 · June 2026 · Snapback Health Technologies LLC

1. Our Core Principles

Principle 1
AI assists, humans decide

Artificial intelligence in our platform is an assistive tool. AI does not make autonomous clinical decisions, modify clinical records without confirmation, or replace the judgment of licensed providers. Every AI-suggested data entry requires the patient to review and confirm before it is saved.

Principle 2
Clear scope, clear limits

AI in Snapback Health is used for patient education, data capture assistance, and routine triage. It is not a diagnostic tool. Wound assessment AI explicitly states it is not a medical diagnosis and instructs patients to contact their care team for any concerns.

Principle 3
Auditability by default

Every AI interaction is logged with timestamp, user identifier, input context, output content, and patient confirmation status. Logs are retained for clinical and compliance review.

Principle 4
Defer to the care team

For any clinical concern, abnormal finding, or patient question outside routine recovery education, the AI directs the patient to contact their clinical care team. The AI is configured to be conservative rather than confident when clinical risk is present.

2. AI Use Cases in Our Platform

Snapback Health uses AI in the following defined ways:

AI Recovery Assistant
Patients can ask questions about their procedure, exercises, expected timeline, and recovery milestones. AI responses are grounded in procedure-specific clinical protocols.
AI Data Logging
Patients speak naturally about vitals, medications, exercises, meals, sleep, or bowel movements. AI parses the input and shows a confirmation card. The patient confirms before any data is saved.
AI Wound Assessment
Patients photograph their incision. AI describes what it observes and provides a three-level triage: looks normal, monitor closely, or contact care team. Explicitly not a diagnosis.
AI Clinical Summarization
Providers receive concise summaries of patient-reported data to support efficient chart review. Underlying data remains the source of truth.

3. What Our AI Will Never Do

The AI in Snapback Health does not and will not:

4. Safety Mechanisms

Every AI interaction in our platform follows these safeguards:

5. Data Handling and Vendor Compliance

Patient health information transmitted to or processed by AI is governed by our Privacy Policy and Business Associate Agreement framework. Our data infrastructure runs on HIPAA-eligible cloud services under signed Business Associate Agreements where applicable.

Category Approach
AI inference Claude models. Protected health information is removed at the application boundary before any inference call. Migration to Amazon Bedrock — Claude hosted within our AWS account under the AWS Business Associate Agreement — is in progress to bring inference fully inside the HIPAA compliance perimeter.
Data retention by AI vendors Zero data retention configuration is our target architecture. AI providers do not train on Snapback Health patient data.
Encryption TLS 1.2+ in transit. Encryption at rest at the database layer.
Audit logging All AI interactions logged to immutable audit trail with patient consent and confirmation status.
Cloud infrastructure HIPAA-eligible AWS services under the AWS Business Associate Agreement (executed May 30, 2026; account designated as a HIPAA Account).

6. Human Oversight

Snapback Health is a clinician-led platform. Clinical content — procedure protocols, exercise plans, recovery timelines, red flag criteria — is reviewed and approved by qualified clinical personnel before deployment. AI output is grounded in this clinician-approved content.

Providers retain full authority over their patients' care. The platform supports clinical decision-making; it does not substitute for it.

7. Incident Response

If an AI output contributes to or fails to identify a clinical concern, we take the following steps:

Care teams and patients can report concerns about AI behavior to our privacy team at any time.

8. Patient Transparency

Patients are informed in plain language that:

9. Frameworks We Reference

Snapback Health's approach is informed by the following frameworks and standards:

Formal certifications such as SOC 2 Type II and HITRUST alignment are on our roadmap as the platform matures and patient volume grows.

10. Roadmap

We are committed to continuous improvement of our AI governance. Near-term priorities include:

Questions about our AI governance?

We welcome dialogue with clinics, partners, regulators, and patients on responsible AI in healthcare.

Privacy and compliance contact:
privacy@snapbackhealth.com

General inquiries:
john.oshea@snapbackhealth.com

Snapback Health Technologies LLC
210 West Cedar Avenue, Flagstaff, AZ 86001