Adjudica source release 2026.08.24 · runtime and legal approval not implied
Skip to main content
Source-Observed Security Design

Review Contracts, Providers, and Runtime Controls Before PHI Use

This page summarizes configuration and document evidence. It does not certify HIPAA, CCPA, GDPR, SOC 2, Bar-rule, or customer-specific compliance, and it does not establish observed-live control operation.

Contract review

Confirm BAA and PHI terms for the customer environment

Provider review

Confirm enabled routes and vendor coverage before PHI use

Control review

Validate runtime security controls independently

Attorney duty

Professional and confidentiality obligations remain with counsel

Security Architecture

Configured Controls Require Environment-Specific Verification

Architecture and policy sources describe intended safeguards. Confirm deployment, contracts, provider routes, tenant controls, logging, retention, and incident procedures for the customer environment before relying on them.

BAA and PHI Workflow Review

Confirm Before PHI

Source materials include BAA and data-handling documents. Availability, execution, scope, provider coverage, and customer eligibility must be confirmed before PHI use. Documentation does not certify HIPAA compliance.

Data-Use and Retention Terms

Source documents describe intended data-use, retention, processing-location, and vendor restrictions. Confirm the executed customer and provider terms; this release did not independently observe retention or training behavior.

Multi-Tenant Data Isolation

Source configuration describes firm- and matter-scoped access with application roles. Runtime tenant isolation and authorization behavior require independent testing in the customer environment.

Encryption at Rest and in Transit

Architecture and policy sources describe encryption in transit and at rest. Algorithm, endpoint, key-management, and coverage details must be confirmed for the deployed environment; this release did not inspect runtime traffic or stored data.

Audit and Activity Records

Source configuration describes selected audit and activity records. Coverage, retention, integrity, and access-report completeness were not independently observed and must be verified for the deployed environment.

Incident-Response Documentation

Incident-response and notification documents exist in the source family. Applicable deadlines and operational readiness depend on jurisdiction, contract, facts, and implemented controls and require independent review.

Attorney Responsibilities

Product Features Do Not Establish Professional Compliance

Counsel remains responsible for understanding AI limits, protecting confidentiality, supervising work product, and verifying outputs under the rules applicable to the engagement.

Rule 1.1: Competence

Review available product documentation and independently assess relevant limitations. Source attribution is workflow-dependent and not guaranteed.

Rule 1.6: Confidentiality

Confirm the executed contract, provider path, access controls, retention terms, and confidentiality safeguards before processing client information.

Rule 5.3: Supervision

Attorneys remain responsible for AI-assisted work product. Configured review gates support that duty but do not replace supervision or prove every runtime path.

COPRAC November 2023

Verify AI-assisted output before use. Follow available source links, inspect the complete record, and confirm governing law because citations can be absent or wrong.

Policy and Contract Documents

Documents Are Available for Independent Review

The source tree contains corporate, product, privacy, and regulatory documents. Their existence does not establish completeness, legal approval, execution, operational readiness, or compliance.

Examples: corporate documents

  • Privacy Policy
  • AI Governance Policy
  • Data Handling Policy
  • Data Retention Policy
  • Incident Response Policy
  • Law Enforcement Guidelines

Examples: product documents

  • End User License Agreement
  • Terms of Service
  • Business Associate Agreement (HIPAA)
  • AI Transparency Disclosure
  • HIPAA-related documentation

Examples: regulatory references

  • CCPA/CPRA materials
  • CMIA materials
  • CalOPPA materials
  • SOC 2 planning materials
  • California Bar guidance references

Attorney-Client Privilege Safeguards

Architecture Alone Does Not Guarantee Privilege or Confidentiality

Source configuration describes tenant scoping, role-based access, and contractual protections. Those measures may support confidentiality, but privilege and legal effect depend on the engagement, use, contracts, disclosures, and implemented controls. Obtain appropriate legal and security review.

Firm-Level Scoping

Configured tenant separation; runtime testing required.

Matter-Level Access

Configured role permissions; effective access must be verified.

Provider Data Terms

Confirm customer-specific provider and training terms before use.

Request Contract and Security Review Materials