> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-hypeship-docs-ia-v2.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# HIPAA

> Run browser workflows that handle protected health information on KERNEL's Enterprise plan

KERNEL supports HIPAA compliance for workflows that handle protected health information (PHI), and signs a business associate agreement (BAA) on the Enterprise plan.

## What KERNEL provides

* **A BAA.** KERNEL signs a BAA with Enterprise customers. [Contact sales](/info/contact-sales) to start one.
* **Isolation per browser.** Each browser runs in its own VM with its own kernel and filesystem, isolated from other sessions at the hypervisor.
* **Zero data retention.** With [zero data retention](/info/zero-data-retention), session recordings, live view streams, and telemetry aren't retained after a browser terminates. Turn it on if PHI must not persist after a session ends.

## What you're responsible for

HIPAA compliance is shared. KERNEL secures the platform; you're responsible for how your agents use it, such as which sites they access, what data they extract, and where that data goes. See the [shared responsibility model](/shared-responsibility-model) for the full split, and [security practices](/security) for KERNEL's program and current compliance status.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.