Skip to content
Weave templates

HIPAA — PHI Data Flow

Where PHI lives, who can touch it, and the encryption boundary.

Template previewWeave
Rendering…

Make it your own.

{
  "nodes": [
    { "id":"pt","type":"ellipse","label":"Patient","x":40,"y":160,"fill":"#dcfce7" },
    { "id":"app","type":"rect","label":"Patient portal\n(TLS, MFA)","x":220,"y":160,"fill":"#dbeafe" },
    { "id":"api","type":"rect","label":"API\n(HIPAA-eligible)","x":420,"y":160,"fill":"#dbeafe" },
    { "id":"phi","type":"rect","label":"PHI store\n(encrypted at rest)","x":620,"y":80,"fill":"#fef3c7" },
    { "id":"deid","type":"rect","label":"De-id pipeline","x":620,"y":260,"fill":"#ede9fe" },
    { "id":"wh","type":"rect","label":"Analytics warehouse\n(de-identified)","x":820,"y":260,"fill":"#ede9fe" },
    { "id":"baa","type":"note","label":"All vendors covered by BAA — access logged for 6 years","x":420,"y":40,"fill":"#fef9c3" }
  ],
  "edges": [
    { "id":"e1","source":"pt","target":"app","label":"HTTPS" },
    { "id":"e2","source":"app","target":"api","label":"mTLS" },
    { "id":"e3","source":"api","target":"phi" },
    { "id":"e4","source":"phi","target":"deid","label":"safe-harbor","style":"dashed" },
    { "id":"e5","source":"deid","target":"wh" }
  ]
}