HIPAA compliant clinical reasoning, with zero retention of your data
The EvidenceMD API answers clinical questions with peer-reviewed citations, and it does so without keeping what you send. Zero retention of your prompts and responses. No training on your data. A signed BAA for workloads involving patient information.
Zero retention
Your prompts and our responses are not retained once the call completes. There is nothing to configure and nothing to enable — it applies to every request, on every plan.
No training on your data
Your content is never used to train, fine-tune, or evaluate any EvidenceMD model. No opt-out to find, no setting to police.
You own your data
You retain ownership of your inputs and the outputs the API returns, and you are free to use them in your product under your agreement.
Commitments
What we commit to
Six commitments, in plain terms. Each one is written into your Enterprise agreement, so it is contractual rather than aspirational.
Status
Compliance
HIPAA
CompliantBuilt for HIPAA-regulated workloads, with a Business Associate Agreement executed before any patient data flows.
SOC 2 Type II
In progressAudit underway. Contact us for the current status and expected timeline.
Zero retention
ActiveIn force on every request today, by default, on every plan — not an add-on and not a setting.
Infrastructure
Security
Encryption
Traffic is encrypted in transit with TLS 1.2 or higher, and everything we store is encrypted at rest with AES-256. Plain HTTP is not accepted.
Access control
Every request is attributed to a specific API key, so usage traces to a team or environment. Keys are shown once, can be revoked instantly, and are rate limited individually.
Enterprise
What Enterprise includes
BAA for patient data
A Business Associate Agreement scoped to the clinical workflow you are actually building, signed before any PHI flows.
Raised rate limits
Standard access allows 60 requests per minute per key. Enterprise limits are set to your expected peak, agreed in writing.
Volume pricing
Committed-use pricing with invoicing, purchase orders, and annual terms in place of per-credit card payments.
Key governance
Separate keys per environment, a documented rotation procedure, and immediate revocation when a key needs to be retired.
Support and reporting
Defined availability targets, response times by severity, a named contact, and usage reporting at the interval your team needs.
Contracted terms
Data processing terms, retention commitments, and post-termination handling written into your agreement, not just documentation.
FAQ
Common questions
Do you retain the prompts and responses sent to the API?
No. We operate zero retention on your request and response content. It is not retained once the call completes. We keep only usage metadata such as which key called, the endpoint, status, latency, and credits used, which is what billing and support require.
Is the EvidenceMD API HIPAA compliant?
Yes. The API is built for HIPAA-regulated workloads, with zero retention of clinical content, encryption in transit and at rest, per-key access control, and usage records that contain no PHI. For workloads involving patient data we execute a Business Associate Agreement as part of Enterprise onboarding.
Do you sign a Business Associate Agreement?
Yes. A BAA is executed as part of Enterprise onboarding, before any patient data flows through the API. Write to krishnakumar@evidencemd.ai describing your clinical workflow and we will scope the agreement to it.
Do you train on our data?
No. Your prompts and responses are never used to train, fine-tune, or evaluate any EvidenceMD model. There is no setting to change and no opt-out to manage.
Who owns the inputs and outputs?
You do. You retain ownership of what you send and what the API returns, and you are free to use the outputs in your product under your agreement with us.
Are you SOC 2 certified?
SOC 2 Type II is in progress. Contact us for the current status and expected timeline.
Can you retrieve what the API returned last week?
No, and this is worth factoring into your own design. We can confirm that a call occurred, when it happened, how long it took, and whether it succeeded. We cannot reproduce the question or the answer, because neither was retained. If you need an audit trail of clinical content, keep it on your side.
Is no-training the same as zero retention?
They are separate commitments and you should ask any vendor about both. No-training means your content is never used to improve a model. Zero retention means your content is not kept after the request. EvidenceMD commits to both.
What are the rate limits and uptime commitments?
Standard access allows 60 requests per minute per API key, with best-effort availability and email support. Enterprise agreements carry raised limits set to your expected peak, defined availability targets, response-time commitments by severity, and a named contact.
Talk to us
Tell us the clinical workflow you are building, your expected volume, and whether patient data is involved. We will come back with the agreements your workload needs and pricing.
Contact usPrefer to evaluate first? Get a self-serve API key and read the API reference.
Last updated August 8, 2026. Contractual terms for your organisation are governed by your agreement with EvidenceMD.
