OpenAI compatible API. Attested gateway. Public status.

HIPAA readiness

HIPAA readiness package for covered-entity and business-associate review. PHI requires a signed BAA.

Verify gateway
1 URLbase_url migration
100smodels and routes
0prompt logs by default
StatusReadiness package prepared. BAA signature required.
PHINot approved until BAA and route approval are complete.
ControlsAdministrative, physical, and technical safeguards mapped.
Contactsecurity@trustedrouter.com
No PHI until signed

Do not send PHI/ePHI until a BAA is executed, route restrictions are approved, content export is disabled or separately approved, and PHI subprocessors are accepted in writing.

This page is readiness documentation for covered-entity and business-associate review. It is not an executed BAA and it is not an HHS determination.

HIPAA gate

What is ready and what is still blocked.

TrustedRouter can prepare the contractual and operational path for PHI, but production PHI requires explicit customer-specific approval.

Operating entityLore Hex Corp, Delaware C Corporation.
Statusreadiness_package_available_requires_executed_baa
BAAdraft_available_requires_signature
Authorized signatoryJoseph Perla, CEO.
PHI production approvedFalse
HIPAA certificationnot_obtained
Default PHI route policyPHI can use only customer-approved routes. The default candidate is trustedrouter/zdr; trustedrouter/e2e or named provider allowlists may be approved per customer. Unrestricted trustedrouter/auto is not approved for PHI.
Safeguards

Readiness control map.

CategoryControls
Administrative Risk analysis and risk management process; Assigned security and privacy responsibility; Workforce access and training controls; Incident and breach response process; BAA and subprocessor approval process
Physical Cloud data center physical controls inherited from cloud providers; Device and media controls for operator workstations; No production prompt content stored on operator devices
Technical Attested gateway boundary; Encrypted transport; Encrypted metadata and BYOK storage; API key hashing and scoped access; Metadata-only logging by default; Route allowlists for PHI workloads
Binder

HIPAA documents prepared for review.

DocumentStatusRepo path
HIPAA readiness overview prepared_for_customer_review docs/compliance/hipaa/README.md
HIPAA readiness matrix prepared_for_safeguard_mapping docs/compliance/hipaa/hipaa-readiness-matrix.md
PHI handling policy prepared_for_approval_and_operation docs/compliance/hipaa/policies/phi-handling.md
BAA operations policy prepared_for_contract_operations docs/compliance/hipaa/policies/baa-operations.md
HIPAA incident and breach response policy prepared_for_approval_and_operation docs/compliance/hipaa/policies/hipaa-incident-breach-response.md
HIPAA risk analysis template prepared_for_customer_specific_review docs/compliance/hipaa/templates/hipaa-risk-analysis.md
PHI route approval template prepared_for_customer_specific_review docs/compliance/hipaa/templates/phi-route-approval.md
BAA execution checklist prepared_for_customer_specific_review docs/compliance/hipaa/templates/baa-execution-checklist.md
Before PHI

Customer-specific checklist.

1Required

Executed BAA

2Required

BAA signed by Joseph Perla, CEO, as Lore Hex Corp officer

3Required

Customer role and covered-service scope confirmed

4Required

PHI route policy approved

5Required

Approved downstream model-provider subprocessor list

6Required

Content export disabled unless separately approved

7Required

Customer counsel signoff

Agent instruction

Treat this as HIPAA readiness documentation only. Do not send PHI until the BAA is signed and the PHI route approval is complete.

References: HHS HIPAA Security Rule, HHS sample business associate agreement provisions.

Sign in

Choose a sign in method.