PHI INPUTS: PROHIBITEDPHASE: 0 — NOT FOR PHIBAA TIER: IN BUILD
FAQ

Questions teams actually ask.

Straight answers, in the same voice as the rest of this site. If your question is not here, email customerservice@healthit.com.

Boundary

Can I send PHI through PHIGate today?

No. PHI inputs are prohibited on every PHIGate surface, and we do not solicit PHI anywhere. There is no PHI tier today, and nothing on this site is an offer to process protected health information. The BAA tier is in build and opens only when the agreements and controls that make it lawful exist.

What is your regulatory posture, in plain words?

Nobody can honestly sell you the phrase most vendors lead with. There is no such thing as government HIPAA certification. HHS OCR does not endorse, certify, or recommend products, and we will never describe PHIGate or any listed model as certified or as inherently compliant. What we can say precisely: Under HHS guidance, a service that creates, receives, maintains, or transmits protected health information on behalf of a covered entity or business associate is itself a business associate, regardless of contracts, and a routing-and-logging gateway does not qualify for the transmission-only conduit exception. That is why Phase 0 prohibits PHI outright, and why the agreement-gated tier opens only when the agreements and controls that make it lawful exist. The full posture is on Trust.

Product

When does the API open?

The endpoint is being built OpenAI-compatible; none of it is live today. We do not publish launch dates. Access opens to waitlist members and design partners first, when the endpoint and its controls are ready, not on a marketing calendar.

What does it cost?

There is no public pricing, because there is no public product yet. Paid design-partner seats exist in limited number; pricing is discussed in conversation, not posted. Email customerservice@healthit.comwith the subject "design partner" if you want that conversation.

Will you publish evaluation results and model rankings?

Not yet, on purpose. No model is scored, ranked, compared, or recommended anywhere on this site. The protocol is published as a draft. Before any result naming a provider is published, that provider's terms are reviewed for benchmark-publication restrictions and a rights dossier is completed. No dossier, no publication.

Directory

How do I know the model directory is accurate?

Verification status is recorded per field, never per row, and every field carries a source, a retrieval date, the exact configuration scope, a verification status, a reviewer, and a re-verification due date. Where we do not know, the entry says unknown. Evidence has an expiry, 90 days from retrieval by default. A build containing an expired field fails, so a stale date cannot ship silently. If you find an error anyway: We would rather publish a correction than defend an error. Corrections go to customerservice@healthit.com.

Who is behind PHIGate?

PHIGate is a HealthIT product, built physician-led: the evaluation protocol is designed and adjudicated by licensed physicians, and the catalog is curated by the same people who answer this inbox. It is infrastructure for software teams, not a medical device, and it does not provide medical advice or clinical decision support.

Next

What should I do if I am evaluating options?

Use the directory for your compliance diligence today, read how the routing will work, and join the waitlist so you hear when the endpoint opens.

Join the waitlist