PHI Infrastructure Checklist

Submit to GoDaddy/Airo support before enabling real PHI collection

Current PHI Authorization Status

Airo PHI storage / processing
NOT APPROVED — UNVERIFIED
Real PHI collection
DISABLED
Application-layer security controls
PASSING
BAA with GoDaddy / Airo
NOT CONFIRMED
Do not accept a generic response such as "GoDaddy supports HIPAA." Every answer must apply specifically to Airo AI Builder and the services used by this exact application.

Product Authorization

Q1

Is Airo AI Builder authorized by GoDaddy for storing or processing PHI as defined under HIPAA?

Q2

Will GoDaddy execute a BAA that explicitly covers Airo AI Builder?

Q3

Does that BAA explicitly cover the managed MySQL database provisioned by the Airo database skill?

Q4

Does the BAA explicitly cover /private/ application file storage?

Q5

Does the BAA cover backups and disaster-recovery copies of the MySQL database and /private/ storage?

Q6

Does the BAA cover Cloudflare CDN / reverse-proxy processing of requests to this application?

Q7

Does the BAA cover the Airo supervisor proxy and build infrastructure?

Q8

Does the BAA cover application logs and error logs generated by this application?

Subprocessors

Q9

Which subprocessors may receive or have access to PHI processed through an Airo AI Builder application?

Q10

Are all subprocessors covered under appropriate BAAs or equivalent contractual protections?

Technical Infrastructure

Q11

Is the managed MySQL database encrypted at rest? What encryption standard is used (e.g., AES-256)?

Q12

Is /private/ application file storage encrypted at rest? What standard?

Q13

Is /private/ storage persistent across redeployments and container restarts? What is the data retention guarantee?

Q14

Are database backups encrypted at rest? What is the backup retention period?

Product Terms and Plan Requirements

Q15

Is PHI storage and processing explicitly permitted under the Airo AI Builder product terms for this account's current plan?

Q16

Is there a specific Airo AI Builder plan or tier required for HIPAA-eligible workloads? If so, what is it and how is it obtained?

Copies all 16 questions formatted for GoDaddy support

After Receiving Written Confirmation

After receiving written confirmation and a signed BAA: set PHI_COLLECTION_ENABLED=true in app secrets, update this document with the BAA date and support ticket number, and notify the CNY Neurological compliance officer before enabling live submissions.

Share Your Experience

Your feedback helps us continue improving the experience we provide our patients.

Leave a Review