Hey Eduardo runs entirely on your Mac. PHI never leaves your device. There is no third party to sign a BAA with — because there is no third party receiving client data. The HIPAA question becomes structurally moot.
Consumer ChatGPT, Claude.ai, and Gemini retain inputs by default. For a covered entity, that's a third-party disclosure of PHI without a Business Associate Agreement — a textbook HIPAA breach.
Pasting session notes, intake forms, or any patient-identifying information into ChatGPT or Claude.ai constitutes a disclosure to a third party without a BAA — a HIPAA violation.
Even enterprise AI tools require careful BAA negotiation, contract review, and ongoing vendor oversight. Most solo and small-group practices don't have time or legal support for this.
HHS OCR proposed the first major HIPAA Security Rule update in 20 years (January 2025), citing the rise of AI tools and ransomware. New standards favor data-minimization architectures.
Hey Eduardo runs the AI model on your Mac. When you paste in a session note, ask about a treatment approach, or draft a referral letter, the PHI is processed by your local hardware. It is not sent to any server. It is not stored by any vendor. It is not used to train any model.
The HIPAA analysis becomes structurally simple: there is no third party receiving PHI, so the rules governing PHI disclosure to third parties do not apply. The Business Associate Agreement question becomes moot because there is no business associate.
Type or paste raw session notes. Ask Eduardo to format them into SOAP, DAP, or your preferred structure. Review and edit before saving.
Discuss diagnostic considerations, evidence-based interventions, and treatment plan formats without sending case material to a third party.
Paste in journal articles, CE course materials, or DSM-5 sections and ask for plain-language summaries. Stay current without overwhelming your reading list.
Because Hey Eduardo runs entirely on your Mac and PHI never leaves your device, there is no data transmission to evaluate and no BAA needed. The architectural protection is stronger than any contractual one.
No. BAAs are required when sharing PHI with a third-party service provider. Hey Eduardo doesn't receive PHI — it processes everything on your local device.
Not directly. Eduardo reads text you highlight from any application. Copy a note from your EHR, paste it into Eduardo, and ask. The EHR data stays in the EHR; the Eduardo conversation stays on your Mac.
Conversation history lives in memory only. Close Eduardo and it's gone — no log files, no history stored on disk. By design.
One-time purchase from $49. 14-day money-back guarantee. Apple Silicon Macs only.