How does AskMD handle PHI, privacy, and HIPAA compliance?

EMPLOYERS Updated August 2026

AskMD is built for regulated healthcare. Sharecare acts as a business associate under HIPAA for covered entity programs, complies with the HIPAA security rule, and runs industry-leading security practices including ISO 27001 and HITRUST, with clinical safety and content policies enforced on every AskMD interaction and human oversight built in.

Individual privacy holds at the organizational level by policy: protected health information is never shared with an employer for employment-related purposes. Organizations receive what is needed to administer their program, such as completion status but not results, plus aggregate, de-identified reporting on program performance. Member conversations in AskMD are never shared with the sponsoring organization.

Members see the same commitments directly: a health data privacy notice at signup, identity verification through CLEAR, no sale of personal health information, and no use of personal health data to train AI models. Trust the members can verify is part of what organizations are buying.