Notifications
You're all caught up.

AI does the drafting. You do the deciding.

Sherpa is the AI inside HIPAA Sherpa. It reviews your evidence against the regulation, drafts what it would write, and shows its reasoning so you can check it. What it never does is decide. Every output arrives as a proposal that a person accepts, edits or throws away — and your compliance record only ever contains what a human put there.

Compliance is a judgement call. Software should not pretend otherwise.

A HIPAA assessment is a statement your organization makes about itself, to a regulator, under its own signature. Handing that judgement to a model would be a bad trade even if the model were never wrong — because when an investigator asks why you answered the way you did, “the software decided” is not an answer.

So Sherpa is built to take on the part that is genuinely slow, and to leave alone the part that is genuinely yours.

It works through the regulation so you are not holding hundreds of requirements in your head. It reviews the evidence you attached and tells you where it falls short of what the requirement asks for. It drafts the remediation plan you were going to write anyway.

Then it stops, and waits for you.

Four controls, enforced in the product

These are not policy statements. They are how the software behaves.

It is off until you turn it on

AI is disabled for every new organization. Enabling it is an explicit decision an admin makes, after reading exactly what would be sent and to whom. Nothing reaches a model before that.

It never overwrites your answer

When Sherpa reviews an assessment item, its verdict, confidence and reasoning are stored beside your answer, never on top of it. Your answer stays the one you gave. The review is an annotation you can read, weigh and ignore.

You can overrule it, on the record

Disagree with a verdict and you overrule it with a note saying why. The override is stored with your name and the time, so the disagreement becomes part of the evidence rather than a silent edit.

A new review needs new attention

If the answer or its evidence changes, Sherpa reviews it again — and deliberately clears your previous override. A judgement you made about the old evidence is not allowed to stand as approval of the new.

Drafts work the same way. Sherpa can write a remediation plan, a policy, a risk entry or a suggested answer — and every one lands in front of you as a proposal with an Apply button. If you never press it, nothing was written.

Most of this product is not AI, on purpose

Roughly a third of the services in HIPAA Sherpa involve a model. The rest are ordinary code, because ordinary code is better at their job.

Answered by code

Deterministic, repeatable, identical every time you ask.

  • Your compliance score. Arithmetic over your own answers. A model would only make it less predictable.
  • Which evidence has gone stale. A date comparison. Whether a file is older than a year needs no judgement.
  • Duplicate evidence. A checksum. Two files either match exactly or they do not.
  • Which controls your policies cover. Structural mapping between the requirements a policy cites and the controls they belong to.
  • Every statutory deadline. Counted from the dates you enter, never estimated.

Helped by Sherpa

Where the question genuinely needs reading comprehension, or a first draft.

  • Does this evidence support this answer? Comparing a document against a requirement is reading work, and it is the slowest part of an assessment.
  • What does this requirement mean for us? Plain-language explanation of a regulation, grounded in your own answers.
  • Write me a starting point. Policies, remediation plans and risk entries you then edit into something true for your organization.
  • What should we do next? Your open work ranked by impact, from your data alone.

The dividing line is simple. If a question has a correct answer that can be computed, we compute it. If it needs someone to read a document and form a view, Sherpa drafts the view and you confirm it. Putting a model in front of a date comparison would be worse software wearing a better badge.

What Sherpa is not allowed to do

Restrictions built into the product, not intentions we hold.

  • It does not answer your assessment. It can draft a suggested answer for you to review. Applying it is a person's action, and the record shows which person.
  • It does not sign anything. Signing an assessment requires a real person re-entering their password and a second factor. No AI path reaches a signature.
  • It does not decide whether a breach is notifiable. That determination carries legal consequence and belongs to your privacy officer. Sherpa helps you organize the incident; the deadlines are counted by code from the dates you enter.
  • It does not go looking for patient data. Most of what Sherpa sees is counts, labels and regulatory text. The two features that review your uploaded evidence send that file content — which may contain PHI — to the same BAA-covered, zero-retention service, and the model is instructed to judge it without ever quoting a patient identifier or record back to you.
  • It does not take instructions from your documents. Everything you upload is treated as material to analyze, never as commands. Text inside a file that tries to steer a verdict is itself treated as a warning sign, and resolved conservatively.
  • It does not fill gaps with plausible guesses. Where your data does not support a conclusion, Sherpa says the data is missing and names what you would need to capture. Silence is reported as silence.

The regulatory content Sherpa reasons from is ours, and it is reviewed

Sherpa does not know HIPAA because it read the internet. It works from a question bank and policy library that certified healthcare security and privacy practitioners — holding CISSP, CISA and AI-governance credentials — wrote, cited and reviewed.

Reviewed before every release

When a question, a citation or a policy statement changes, the release stops until a specialist review pass has covered it — Security Rule, Privacy and Breach rules, and the generated policies.

Every requirement carries its source

Questions cite the provision they implement, so you can check the regulation yourself rather than taking our word for it, or Sherpa's.

Guided engagements add a named reviewer

On a guided assessment a practitioner works through your answers item by item and countersigns the finished report. You see who reviewed it.

A regulatory claim does not reach you because a model was confident about it. It reaches you because a person put it there and stood behind the wording.

What is sent, and what happens to it

When you enable AI, the compliance material Sherpa needs — assessment answers, notes, evidence file contents and related records — is sent to a third-party AI service for analysis. That service operates under a business associate agreement that provides for zero retention and no training on your data.

We tell you this before you switch it on, in those words, because your organization needs to confirm the arrangement fits its own privacy posture and BAA obligations. If it does not, leave AI off — everything else in HIPAA Sherpa works without it.

Read our full security posture →

See where it helps, and where we left it out

Start an assessment and judge Sherpa on its drafts. You are the one who decides what goes into the record.