ReadyAED

HIPAA and data handling for AED programs

What the platform stores, when a BAA is available and what is not confirmed yet.

What PHI (if any) is handled

You handle compliance for an AED (automated external defibrillator) program, or you review software for one. You need a straight answer about HIPAA (the Health Insurance Portability and Accountability Act). This page states what ReadyAED confirms today. It also names the questions that do not have a published answer yet. Two questions come up first: what data is stored, and whether a BAA is available. ReadyAED is software only. Your legal or security team can ask for a BAA during procurement, so the request path sits below.

PHI (protected health information) is health information that identifies a person. ReadyAED stores AED program records. Your team creates the content that goes into the platform: inspection answers, notes and photos. Most of that content describes devices, not people. Most inspection content describes a device: its pads, battery, cabinet and rescue kit. A device record holds a serial number, a location and inspection answers. None of those fields identifies a patient by itself. A serial number on its own is not health information.

A free-text note or a photo can change that. A note or a photo can hold health details if your team puts them there. When that happens, the content sits in the inspection record. Notes and photos are optional on every inspection, so an inspection can be completed with no free text and no photo. Whether your use of the platform involves PHI depends on your program and your data. product confirmation required before publishing this claim

BAA availability

A BAA (Business Associate Agreement) is available. BAA request process and turnaround — legal confirmation needed

A BAA sets the terms for protected health information when one organisation handles it for another. A BAA does not change what the software does. It sets the terms for the data. ReadyAED makes no other HIPAA claim. It does not claim HIPAA certification or HIPAA compliance. Ask for the BAA through the Contact page and choose security. Ask during procurement or during a security review. Keep a copy with your program documents.

This page is general information, not legal advice. legal-approved disclaimer text this passage needs legal sign-off

What data is stored

ReadyAED stores these records in one account:

  • The organisation account, and user records with work email, name and initials. User records show a name, an initials avatar and the organisation.
  • Sites and locations, with building, floor and room paths. Location updates are kept in device history.
  • AED device records: brand, model, serial number, asset ID, installed date, pads expiry, battery percentage and status.
  • Inspection records: date, inspector, five checklist answers, result, battery reading, optional notes and photos.
  • Follow-up tasks, created when a checklist line fails.
  • Documents: manuals, certificates and service records. Documents are uploaded and downloaded per device only.
  • Alerts and five email templates: inspection due, overdue, device used, weekly digest and invite.
  • The audit trail: user and system events, device history and inspection history.

Photos are JPG or PNG, 10 MB or smaller, from the camera or the library. The audit trail shows the latest events in the activity feed and keeps the full log. The register covers the whole fleet, and each device keeps its own record. Devices are assigned to a person, and the site custodian and last inspector are shown on the device record. The platform has no physician-oversight screens.

Device detail screen with the Documents tab open, listing a user manual, the AED registration record and a service report for one AED; sample data from the demo tenant.

Retention

How long ReadyAED keeps each record is not published yet. Retention is a contract and record-keeping question. Ask for the retention terms with the BAA. product confirmation required before publishing this claim

Contact our security team and choose security.

Ask for the BAA, ask about retention, or send a security questionnaire. Bring the questionnaire template your organisation uses, and list the controls you need. Read the Security & Trust Center for the full picture and the Subprocessors page for the vendor list.