No-PHI / No-HIPAA Policy
Effective Date: 1 July 2026
TurboHelp is an AI customer support agent platform for small SaaS teams. TurboHelp is not HIPAA-compliant at launch and does not offer a Business Associate Agreement ("BAA") at launch.
Customer must not submit Protected Health Information ("PHI") or other prohibited sensitive regulated data to the Services unless TurboHelp expressly agrees in writing.
1. No HIPAA Use at Launch
TurboHelp is not designed, configured, represented, or offered as a HIPAA-compliant service at launch.
TurboHelp does not sign BAAs at launch. Without a signed BAA and appropriate product configuration, Customer must not use TurboHelp to create, receive, maintain, transmit, process, or store PHI.
Customer is responsible for determining whether Customer is a covered entity, business associate, subcontractor, or otherwise subject to HIPAA or similar health privacy laws.
2. Prohibited Data
Unless TurboHelp expressly agrees in writing, Customer must not submit:
- Protected Health Information or electronic Protected Health Information.
- Medical records, clinical notes, diagnosis data, treatment data, prescription data, lab results, appointment details tied to health status, or patient communications.
- Health insurance data, member IDs, claims data, benefits data, or eligibility data.
- Payment card data subject to PCI DSS.
- Bank account numbers or full financial account credentials.
- Government IDs, passport numbers, driver's license numbers, Social Security numbers, tax IDs, or similar identifiers.
- Children's data or data from users under the age where parental consent is required.
- Biometric identifiers or precise geolocation data where regulated.
- Credentials, secrets, private keys, or access tokens unless a documented feature expressly requires them.
- Other sensitive regulated data that requires special contractual, technical, or legal safeguards not expressly provided by TurboHelp.
3. Customer Responsibilities
Customer must:
- Configure TurboHelp to avoid collection of prohibited data.
- Avoid connecting knowledge sources or integrations that contain prohibited data.
- Train support teams not to paste prohibited data into TurboHelp.
- Use filters, notices, forms, and workflows to redirect sensitive requests outside TurboHelp.
- Promptly notify TurboHelp at [email protected] if Customer believes prohibited data was submitted.
- Delete prohibited data using available tools where feasible.
Customer remains responsible for notices, consents, lawful bases, data minimization, and compliance obligations for Customer Data.
4. If Prohibited Data Is Submitted
TurboHelp may suspend processing, disable features, delete data, require remediation, or terminate the Account if prohibited data is submitted.
TurboHelp's receipt of prohibited data does not make TurboHelp a business associate and does not create a BAA. TurboHelp does not accept obligations for prohibited data except as expressly required by law or a signed written agreement.
Customer should not rely on TurboHelp for breach analysis, regulatory notification, or compliance remediation for prohibited data unless TurboHelp expressly agrees in writing.
5. AI Features and Sensitive Data
Customer must not use Turbo, Input, Output, prompts, support conversations, knowledge sources, or feedback fields to process PHI or prohibited sensitive regulated data.
AI features may route Input and Output to third-party LLM providers or AI infrastructure vendors as described in the AI Product Terms, Data Use and Model Training Addendum, and Subprocessors List. TurboHelp contractually restricts third-party LLM providers from using Customer Data to train or improve their own models, but this does not make the Services suitable for PHI or other prohibited data.
6. Future HIPAA-Enabled Accounts Placeholder
TurboHelp may consider offering HIPAA-enabled accounts in the future. This feature is not currently available.
Any future HIPAA-enabled account would require, at minimum:
- A signed BAA with Textly Inc. before any PHI is submitted.
- A specific eligible plan or written order.
- Security configuration requirements.
- Approved data retention settings.
- Audit logging.
- Access controls and authentication requirements.
- Product restrictions and disabled features where necessary.
- Subprocessor review and applicable downstream agreements.
- Written implementation instructions.
- Customer confirmation that Customer has configured the Account as required.
This placeholder does not create a current HIPAA-compliant offering and does not authorize Customer to submit PHI.
7. Required Customer Disclosure
Customer should include internal and external instructions that TurboHelp must not be used for PHI or prohibited sensitive regulated data. Suggested internal language:
Do not enter medical, health insurance, payment card, government ID, children's, or other sensitive regulated data into TurboHelp. If a customer provides this information, move the conversation to an approved secure channel and remove the sensitive data from TurboHelp where feasible.
8. Contact
Questions about this policy may be sent to [email protected] or [email protected].