Legal
HIPAA Notice
How Weave supports HIPAA compliance for health systems, and where to direct privacy questions. This notice is separate from our general Terms and Conditions.
Last updated 26 September 2026
Placeholder. This page exists so the footer links resolve during the build. Replace the copy below with reviewed legal text before launch.
Our commitments
Weave is built for PHI from day one. Access is role-scoped, every query is audited, and data in transit and at rest is encrypted.
Business Associate Agreements
We execute a BAA with every covered entity before any PHI is processed, and with each subcontractor that touches PHI.
Breach notification
We notify affected covered entities without unreasonable delay and no later than the timeframe required by the BAA and applicable law.
Privacy contact
Privacy questions and individual-rights requests are routed through your organisation’s administrator or our privacy office.