HIPAA & Business Associate Agreements
Last updated · June 27, 2026
Tactis works with skilled-nursing providers who are HIPAA covered entities. Here’s how we approach protected health information and Business Associate Agreements.
Tactis (a product of Lobi Software Studio, LLC) is built for skilled-nursing providers, who are “covered entities” under the Health Insurance Portability and Accountability Act (HIPAA). When Tactis processes protected health information (PHI) on a customer’s behalf, we act as a business associate under HIPAA, and that processing is governed by the customer’s services agreement and a Business Associate Agreement (BAA), not by our general Privacy Policy.
Business Associate Agreements
We make a BAA available on request to customers who will use Tactiswith PHI. The BAA sets out each party’s responsibilities for safeguarding PHI, permitted uses and disclosures, breach notification, and the return or destruction of PHI at the end of the relationship. For customers operating under a BAA, PHI may be provisioned in a more isolated environment. To request a BAA, contact contact@lobisoftware.com.
How we safeguard PHI
Tactis applies administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of PHI, including:
- Encryption in transit and at rest for data moving to and stored within the service.
- Tenant isolation. Each customer organization’s data is logically separated, and answers are retrieved only from that organization’s own knowledge base.
- Access controls and multi-factor authentication, with access scoped to a user’s organization and role.
- Audit logging of significant activity, so actions can be reviewed.
- Defined retention and deletion. PHI is retained per the customer agreement and returned or destroyed when the relationship ends.
- No model training on your data. We do not use customer data to train AI models, and we use AI providers under terms that prohibit training on the data we send them.
You can read more about our architecture on the Trust & security page.
Minimum necessary and subcontractors
We design Tactis to work with the minimum information necessary for the task at hand. Where we engage subcontractors that may handle PHI in providing the service, we put appropriate agreements in place with them as required by HIPAA, so the same protections flow downstream.
Breach notification
If we discover a breach of unsecured PHI, we will notify affected customers without unreasonable delay and within the timeframes required by HIPAA and the applicable BAA, and we will cooperate with the customer’s own notification obligations.
Infrastructure and controls
Tactis runs on Amazon Web Services (AWS) and uses managed AWS services, including AWS KMS for key management and encrypted storage and backups. While Tactis is not currently SOC 2 certified, the platform is designed around the same control principles. HIPAA and SOC 2 also carry organizational responsibilities that extend beyond any single vendor; covered entities remain responsible for their own policies, workforce training, and safeguards outside the product.
Shared responsibility
Protecting PHI is a partnership. Tactis secures the service and the data within it; customers are responsible for managing their own users and access, using the product in line with their policies and their BAA, and meeting their own HIPAA obligations as a covered entity.
Contact
To request a BAA or ask about our HIPAA practices, email contact@lobisoftware.com.