Security

Security and compliance: how Bond handles PHI

Bond Health reads patient records, calls and texts patients, and helps explain consent forms, so it handles protected health information at every step. Bond is HIPAA compliant and SOC 2 Type I compliant, and its SOC 2 Type II and ISO 27001 audits are underway.⁠[2] This page covers where that PHI goes, the controls around it and the evidence your security reviewer can request.

Last updated Sep 24, 202618 sources

Where does PHI go in a Bond deployment?

Bond touches protected health information (PHI) at four points. Each happens under the business associate agreement (BAA) between Bond and the site or health system, and the platform keeps an audit trail.⁠[1]

  1. 1

    Identify reads the chart

    Identify reads the EHR through FHIR R4 APIs, HL7 v2 where applicable, or an integration partner. It checks structured fields and clinical notes against the study's inclusion and exclusion criteria, ranks candidates, and shows the evidence for each criterion.⁠[1]

  2. 2

    The coordinator reviews matches

    Ranked candidates appear in Bond's dashboard with criterion-to-evidence rationale. Access is set by role, and sign-in can run through the site's own identity provider by SSO.⁠[1]

  3. 3

    Engage contacts the patient

    Engage runs voice and SMS agents from scripts configured for each site and study. The agents pre-screen, schedule, and escalate to a coordinator when needed or when the patient asks.⁠[1]

  4. 4

    Consent support explains, the site consents

    Consent gives plain-language explanations and answers patient questions about the consent form. The investigator or delegated site staff still obtain consent.⁠[1]

Engage also connects directly to Google Sheets, CTMS and calendars.⁠[1] Data synced to one of those falls under that system's access controls, so list each connection in your risk analysis.

How is it configured and checked before go-live?

  • Setup. Implementation covers the EHR connection, security review, audit logging setup and workflow configuration, all in the volume-based platform fee, with no separate integration fee. See pricing.⁠[1]
  • Scripts. Outreach scripts are configured per site and study.⁠[1] FDA expects the IRB to review recruitment material and its mode of communication, so they go in your IRB package.⁠[14] See the IRB and HIPAA outreach guide.
  • Validation. ICH E6(R3) expects computerized systems used in trials to be fit for purpose, for example through risk-based validation, and leaves the investigator to decide whether a service provider is appropriate.⁠[13] Ask Bond how its configuration is tested against your protocol.

How does this compare with a manual workflow?

Where PHI ends up, manual recruitment and Bond
StepCommon manual patternWith Bond
Finding candidatesA coordinator reads charts and copies names and notes into a spreadsheetBond reads records under the BAA and shows matches in the access-controlled dashboard
Sharing the listThe spreadsheet moves by email or a shared drive, outside the EHR's access logsUsers sign in to one dashboard, with access set by role and logged
Contacting patientsStaff call from the list and record outcomes in free-text notesVoice and SMS agents follow the configured script and each contact is logged
Showing who saw whatReconstructed from EHR logs, inboxes and file historiesBond's audit trail of access and actions in the platform

Manual workflows can be run securely; the difference is how many copies of PHI they create.

What does the BAA commit Bond to?

Under HIPAA, a vendor that creates, receives, maintains or transmits PHI on behalf of a covered entity is a business associate.⁠[4] Bond is one and signs a BAA with each site or health system.⁠[1] HIPAA requires that written agreement before a business associate handles the site's PHI.⁠[10] The BAA glossary entry covers the required contents. Four terms matter most here:

  • Safeguards. Bond must comply with the HIPAA Security Rule for the electronic PHI it handles.⁠[6]
  • Subcontractors. Any subcontractor that creates, receives, maintains or transmits electronic PHI for Bond must agree to the same requirements in its own contract.⁠[6]
  • Incident reporting. Bond must report security incidents to the site, including breaches of unsecured PHI (timeline below).⁠[6]
  • Return or destruction. When the contract ends, Bond must return or destroy the PHI it still holds where feasible, and extend the contract's protections to anything it cannot.⁠[9]

What about the language models?

A company that hosts a language model and processes chart text or patient messages for Bond is a subcontractor under that rule.⁠[6] HIPAA lets Bond share PHI with it only under a written agreement.⁠[10] Ask which subprocessors, model providers included, handle PHI for your site.

Which security controls does Bond run?

The HIPAA Security Rule names five technical safeguards: access control, audit controls, integrity, person or entity authentication, and transmission security. Encryption is an addressable specification, not a required one.⁠[5] Bond encrypts PHI regardless.⁠[1]

Controls, what Bond does, and the evidence behind each
ControlWhat Bond doesEvidence you can request
Business associate agreementSigns a BAA with each site or health systemBond's BAA for legal review, then the executed copy
Encryption, 45 CFR 164.312(a)(2)(iv) and (e)Encrypts PHI at rest and in transit, using AES-256 where applicableTrust Center, with detail on request from [email protected]
Access control, 45 CFR 164.312(a)Role-based permissions for site, CRO and sponsor usersReviewed with your team during implementation
Authentication, 45 CFR 164.312(d)SSO support, so the site's identity provider controls sign-inSSO configuration during implementation
Audit controls, 45 CFR 164.312(b)Audit logging of access and actions in the platformSet up during implementation; ask which events and fields are logged
Security testingPenetration testing of the platformAsk for the scope and date of the most recent test

Bond's controls as described on bondtrials.com, which also lists employee security training.⁠[1]

What is Bond's compliance status?

  • SOC 2 Type I and HIPAA. Bond is SOC 2 Type I compliant: independent auditor Advantage Partners has issued Bond's SOC 2 Type I report. Bond is also HIPAA compliant, and its SOC 2 Type II and ISO 27001 audits are underway.⁠[2]
  • Trust Center. Bond's Trust Center lists 73 HIPAA Security Rule controls, monitored continuously by Vanta.⁠[3]

How does Bond keep PHI to the minimum necessary?

HIPAA's minimum necessary standard applies to business associates as well as covered entities: make reasonable efforts to limit the PHI used, disclosed or requested to what the purpose needs.⁠[10] Three parts of a Bond deployment bear on it.

  • Screening. Coordinators check the evidence Bond cites for each criterion instead of paging through the whole chart.⁠[1]
  • Outreach content. Scripts are configured per site and study,⁠[1] so your team and IRB decide what a first text says. One option is to leave the condition out of it and confirm identity before discussing the study.
  • Reporting. CRO and sponsor reporting covers enrollment metrics such as patients matched, contacted, consented and randomized.⁠[1] Ask which fields each role can view.

FDA says a simple statement that "confidentiality will be maintained" does not tell the IRB enough about a screening script. Its example questions include what happens to personal information if the caller hangs up, and whether names of people who do not qualify are kept for other studies.⁠[14] Get Bond's answers to both before you submit. The IRB submission language template gives wording sites can adapt.

How long is data kept?

Set retention and disposal terms in the BAA and services agreement. At the end of an engagement, HIPAA requires the business associate to return or destroy the PHI where feasible.⁠[9] For security questionnaires: HIPAA's 6-year retention rule covers security policies and records of required security activities, not the patient data itself.⁠[11]

How are patients told that AI is involved?

Patients contacted by Bond's voice or SMS agents are told AI assistance is used and can reach a person at any time: the agent transfers the call live to a coordinator or books a human callback, whichever the site prefers.⁠[1],[2]

Some states regulate this; two examples as of September 2026. Since January 1, 2025, California has required health facilities, clinics and physician offices that use generative AI for patient communications about clinical information to include an AI disclaimer (spoken at the start and end of a call) and a way to reach a person, unless a licensed provider reviews the message. Scheduling and other administrative matters are excluded.⁠[15] Since January 1, 2026, Texas has required providers that use AI in health care services to disclose it in plain language by the date the service is first provided.⁠[16]

What happens if there is a breach?

A breach at one vendor can reach the patients of many providers at once. HHS's Office for Civil Rights (OCR) reported these figures for 2024 to Congress, as summarized by HIPAA Journal:⁠[17]

663⁠[17]

Breaches affecting 500 or more individuals that occurred in 2024 and were reported to OCR

242.9 million⁠[17]

Individuals whose PHI was exposed or impermissibly disclosed in those breaches

81%⁠[17]

Share of those breaches that were hacking or IT incidents

Most of that total came from a single breach at Change Healthcare, estimated at 192 million individuals.⁠[17] Encryption matters legally: notification duties attach to unsecured PHI, meaning PHI not made unusable, unreadable or indecipherable to unauthorized persons by a method HHS specifies.⁠[8]

If Bond discovers a breach of unsecured PHI, it must notify the site without unreasonable delay and no later than 60 calendar days after discovery, identifying each affected individual where possible.⁠[7] The site, as the covered entity, notifies patients and HHS, and can set a shorter window in the BAA.

What does Bond not do?

  • No FDA clearance. Bond holds no FDA clearance or approval for its software.
  • No IRB approval. Bond claims none. Each site submits its own recruitment materials and chooses its HIPAA pathway, such as a review preparatory to research or a waiver of authorization.⁠[12]
  • No consent on the site's behalf. The investigator or delegated staff obtain consent.⁠[1]
  • No eligibility decisions. Bond ranks candidates and shows its evidence. The study team decides who is eligible.
  • No substitute for the site's HIPAA program. The site remains the covered entity, with its own risk analysis and policies.

What should your security reviewer ask for?

  • Bond's BAA, including subcontractor, incident and termination terms
  • The current list of subprocessors that handle PHI, model providers included
  • Encryption details, and the scope and date of the most recent penetration test
  • A walkthrough of roles, SSO and the audit trail for your site
  • Any Google Sheets, CTMS or calendar connections, and what data each one receives
  • The AI disclosure language the agents use, for your IRB submission

HHS's January 2025 proposed Security Rule update would require encryption of electronic PHI at rest and in transit with limited exceptions, penetration testing at least once every 12 months, and written verification of each business associate's technical safeguards at least once every 12 months.⁠[18] As of September 2026 no final rule had been published, and the eCFR still lists encryption as addressable.⁠[5]

Security review runs inside implementation, and full EHR integration typically takes 48 hours, depending on the EHR, IT review and interface method.⁠[1] See implementation for the plan, and the AI recruitment vendor evaluation checklist to compare vendors.

Bring your security questionnaire. We will walk your IT and compliance team through the data flow, the BAA and the Trust Center.

Frequently asked questions

Does Bond sign a BAA?
Yes, with each site or health system.⁠[1] HIPAA requires that written agreement before a business associate handles the site's PHI.⁠[10]
Is Bond SOC 2 compliant?
Bond is SOC 2 Type I compliant: independent auditor Advantage Partners has issued Bond's SOC 2 Type I report. Bond is also HIPAA compliant, and its SOC 2 Type II and ISO 27001 audits are underway.⁠[2] Its current posture is in its Vanta-hosted Trust Center, and security questions go to [email protected].⁠[1]
Do language model providers see patient data?
Only under a written agreement, which HIPAA requires for any subcontractor that handles PHI for Bond.⁠[6] Ask for the current subprocessor list.

Sources

  1. 1.Bond Health: platform overview, FAQ and pricing · Bond Health, 2026
  2. 2.Bond Health product information · Bond Health, 2026Capabilities, pricing and compliance status described by Bond Health, September 2026.
  3. 3.Bond Health Trust Center · Bond Health, monitored by Vanta, 2026Lists 73 HIPAA Security Rule controls: infrastructure security (20), organizational security (14), internal security procedures (38), and data and privacy (1), monitored continuously by Vanta. Viewed September 23, 2026.
  4. 4.45 CFR 160.103 Definitions (business associate) · eCFR, Office of the Federal Register, 2026Text current as of September 1, 2026.
  5. 5.45 CFR 164.312 Technical safeguards · eCFR, Office of the Federal Register, 2026Quote: "(b) Standard: Audit controls. Implement hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain or use electronic protected health information." and "(iv) Encryption and decryption (Addressable). Implement a mechanism to encrypt and decrypt electronic protected health information." Text retrieved from the eCFR API, current as of September 1, 2026.
  6. 6.45 CFR 164.314 Organizational requirements (business associate contracts) · eCFR, Office of the Federal Register, 2026Quote: "(B) In accordance with § 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information on behalf of the business associate agree to comply with the applicable requirements of this subpart by entering into a contract or other arrangement that complies with this section; and (C) Report to the covered entity any security incident of which it becomes aware" Text retrieved from the eCFR API, current as of September 1, 2026.
  7. 7.45 CFR 164.410 Notification by a business associate · eCFR, Office of the Federal Register, 2026Quote: "a business associate shall provide the notification required by paragraph (a) of this section without unreasonable delay and in no case later than 60 calendar days after discovery of a breach." Text retrieved from the eCFR API, current as of September 1, 2026.
  8. 8.45 CFR 164.402 Definitions (unsecured protected health information) · eCFR, Office of the Federal Register, 2026Quote: "Unsecured protected health information means protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or methodology specified by the Secretary in the guidance" Text retrieved from the eCFR API, current as of September 1, 2026.
  9. 9.45 CFR 164.504(e) Business associate contracts · eCFR, Office of the Federal Register, 2026Quote: "(J) At termination of the contract, if feasible, return or destroy all protected health information received from, or created or received by the business associate on behalf of, the covered entity that the business associate still maintains in any form and retain no copies of such information" Text retrieved from the eCFR API, current as of September 1, 2026.
  10. 10.45 CFR 164.502 Uses and disclosures of protected health information: general rules (minimum necessary; disclosures to business associates) · eCFR, Office of the Federal Register, 2026Quote from (e): "A business associate may disclose protected health information to a business associate that is a subcontractor and may allow the subcontractor to create, receive, maintain, or transmit protected health information on its behalf, if the business associate obtains satisfactory assurances [...] The satisfactory assurances required by paragraph (e)(1) of this section must be documented through a written contract or other written agreement or arrangement with the business associate" Paragraph (b) sets the minimum necessary standard. Text retrieved from the eCFR API, current as of September 1, 2026.
  11. 11.45 CFR 164.316 Policies and procedures and documentation requirements · eCFR, Office of the Federal Register, 2026Quote: "(i) Time limit (Required). Retain the documentation required by paragraph (b)(1) of this section for 6 years from the date of its creation or the date when it last was in effect, whichever is later." Paragraph (b)(1) covers written policies and procedures and records of required actions, activities or assessments. Text retrieved from the eCFR API, current as of September 1, 2026.
  12. 12.45 CFR 164.512(i) Uses and disclosures for research purposes · eCFR, Office of the Federal Register, 2026Text current as of September 1, 2026.
  13. 13.ICH Harmonised Guideline: Good Clinical Practice E6(R3), final version adopted 6 January 2025 · International Council for Harmonisation (ICH), 2025Principle 9.3: computerized systems used in clinical trials "should be fit for purpose (e.g., through risk-based validation, if appropriate)". Section 2.3.1: "The investigator may delegate trial-related activities to other persons or parties. [...] the investigator retains the final decision on whether the service provider intended to support the investigator is appropriate". FDA announced E6(R3) as final guidance on September 9, 2025.
  14. 14.Recruiting Study Subjects: Guidance for Institutional Review Boards and Clinical Investigators · U.S. Food and Drug Administration, 1998Information sheet, January 1998; content current as of 2018. Quote: "A simple statement such as 'confidentiality will be maintained' does not adequately inform the IRB of the procedures that will be used. Examples of issues that are appropriate for IRB review: What happens to personal information if the caller ends the interview or simply hangs up? [...] Are names of non-eligibles maintained in case they would qualify for another study?"
  15. 15.AB-3030 Health care services: artificial intelligence (Chapter 848, Statutes of 2024) · California Legislative Information, 2024Health and Safety Code 1339.75. Operative January 1, 2025. Quote: "For audio communications, the disclaimer shall be provided verbally at the start and the end of the interaction." and "This information does not include administrative matters, including, but not limited to, appointment scheduling, billing, or other clerical or business matters."
  16. 16.H.B. No. 149, Texas Responsible Artificial Intelligence Governance Act (enrolled) · Texas Legislature Online, 2025Business and Commerce Code Sec. 552.051. Effective January 1, 2026. Quote: "(f) If an artificial intelligence system is used in relation to health care service or treatment, the provider of the service or treatment shall provide the disclosure under Subsection (b) to the recipient of the service or treatment or the recipient's personal representative not later than the date the service or treatment is first provided"
  17. 17.OCR Reports to Congress on HIPAA Compliance and Data Breaches in 2024 · HIPAA Journal, 2026Quote: "In calendar year 2024, OCR received 742 reports of data breaches affecting 500 or more individuals; however, only 663 reports related to breaches that occurred in 2024." Also: "Across the 663 reported data breaches, the protected health information of 242,908,056 individuals was exposed or impermissibly disclosed." Also: "hacking/IT incidents, which accounted for 81% of all data breaches" and "The massive total was largely due to a single data breach at Change Healthcare, which affected an estimated 192 million individuals." Article by Steve Alder, May 26, 2026, summarizing OCR's report to Congress; the HHS PDF returned HTTP 403 when fetched.
  18. 18.HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information (proposed rule), 90 FR 898 · Federal Register, U.S. Department of Health and Human Services, 2025Quote: "(B) Penetration testing must be performed at least once every 12 months or in accordance with the covered entity's or business associate's risk analysis required by Sec. 164.308(a)(2), whichever is more frequent." Also: "proposed 45 CFR 164.312(b)(2) would require regulated entities to encrypt all ePHI at rest and in transit, with limited exceptions" and "The Department proposes to require that the regulated entity obtain this written verification documenting the business associate's deployment of the required technical safeguards at least once every 12 months."

Related pages

Ready to get started?

Enroll patients faster.

See how Bond can accelerate enrollment for your clinical trials with a personalized demo.

Book a demo

Up to 3×

faster enrollment

90%+

matching accuracy

4-6 wks

implementation