Data Processing & BAA stance
Draft — last updated August 1, 2026.
Draft pending legal review
Where we stand today
The core Empower GME product — the risk dashboard, AIR generator, action plans, GMEC, APE, and related modules — operates on institutional and program-level data: accreditation status, survey results, metrics, and documents. This is a materially lower risk category than individual patient or trainee health data, and does not, on its own, require a Business Associate Agreement (BAA).
The trainee registry is different
Our roadmap includes an individual-level trainee and graduate registry — identity, credentialing, demographics, Milestones/performance, and visa/health-adjacent fields. This category of data implicates FERPA, and in places potentially HIPAA. That module is built with field-level permissions, read-access logging, and encryption of sensitive fields, but it is disabled by default and enabled for a given institution only once all of the following are in place:
- A signed Business Associate Agreement (BAA) with the institution, and with our hosting provider and any subprocessor that would touch the data.
- A documented, HIPAA-grade operational posture on our side — access reviews, incident response, breach notification procedure.
- A Privacy Policy and Terms of Service that accurately describe the specific data being handled for that institution.
Data Processing Addendum
A Data Processing Addendum (DPA) covering our processing of institutional data generally is available on request for institutional customers.
Questions
If your institution's compliance or legal team has questions about our data handling, reach out through our Contact page — we'd rather answer this up front than after the fact.