Submit to GoDaddy/Airo support before enabling real PHI collection
Is Airo AI Builder authorized by GoDaddy for storing or processing PHI as defined under HIPAA?
Will GoDaddy execute a BAA that explicitly covers Airo AI Builder?
Does that BAA explicitly cover the managed MySQL database provisioned by the Airo database skill?
Does the BAA explicitly cover /private/ application file storage?
Does the BAA cover backups and disaster-recovery copies of the MySQL database and /private/ storage?
Does the BAA cover Cloudflare CDN / reverse-proxy processing of requests to this application?
Does the BAA cover the Airo supervisor proxy and build infrastructure?
Does the BAA cover application logs and error logs generated by this application?
Which subprocessors may receive or have access to PHI processed through an Airo AI Builder application?
Are all subprocessors covered under appropriate BAAs or equivalent contractual protections?
Is the managed MySQL database encrypted at rest? What encryption standard is used (e.g., AES-256)?
Is /private/ application file storage encrypted at rest? What standard?
Is /private/ storage persistent across redeployments and container restarts? What is the data retention guarantee?
Are database backups encrypted at rest? What is the backup retention period?
Is PHI storage and processing explicitly permitted under the Airo AI Builder product terms for this account's current plan?
Is there a specific Airo AI Builder plan or tier required for HIPAA-eligible workloads? If so, what is it and how is it obtained?
After receiving written confirmation and a signed BAA: set PHI_COLLECTION_ENABLED=true in app secrets, update this document with the BAA date and support ticket number, and notify the CNY Neurological compliance officer before enabling live submissions.
Your feedback helps us continue improving the experience we provide our patients.
Leave a Review