QUANTASEAL
QUANTASEAL
QuantaSeal is prepared to execute a Business Associate Agreement (BAA) with Covered Entities and Business Associates handling Protected Health Information (PHI). Complete the form below to initiate the process.
Health records have a 30β50 year relevance horizon. Classical encryption (RSA/ECDSA) will be broken by quantum computers within this window. QuantaSeal applies ML-KEM-768 - NIST FIPS 203 Level 3 - protecting PHI against future quantum adversaries today.
Encryption and decryption of ePHI is an addressable specification. QuantaSeal's AES-256-GCM + ML-KEM-768 hybrid architecture directly satisfies this requirement and produces evidence-grade audit logs.
Every PHI access event is recorded in a SHA3-256 hash-chained audit log stored in S3 WORM. Each entry is ML-DSA-65 signed. HIPAA Β§164.312(b) audit control requirement: satisfied out of the box.
Each covered entity receives a dedicated AWS KMS Customer Master Key. PHI encrypted for Hospital A is cryptographically isolated from Hospital B - zero cross-tenant data access is architecturally impossible.
Role-based access control with viewer/editor/admin/owner roles. API key scoping limits access to specific vaults or operations. MFA and FIDO2 passkeys for all administrative access.
QuantaSeal's incident response engine detects anomalous PHI access patterns in real time. Automated notifications to covered entity within 1 hour of suspected breach - HIPAA Β§164.404 compliant.
Our BAA is consistent with 45 CFR Β§164.504(e) and covers:
Review our standard BAA template before engaging your legal team. The template follows 45 CFR Β§164.504(e) and covers all required provisions. The final executed agreement will be tailored to your organisation.
QuantaSeal HIPAA BAA β Template v1.0
Plain-text Β· Last revised May 2026 Β· 45 CFR Β§164.504(e) compliant structure
After reviewing the template, send us the completed fields to initiate execution. Our healthcare compliance team responds within one business day.
Send your BAA request to hipaa@quantaseal.io with the following information:
Typical response time: 1 business day. BAA execution: 3β5 business days.
| Standard | Specification | Implementation | Status |
|---|---|---|---|
| 164.312(a)(1) | Access Control | RBAC + MFA + FIDO2 passkeys | β |
| 164.312(a)(2)(iv) | Encryption & Decryption | ML-KEM-768 + AES-256-GCM | β |
| 164.312(b) | Audit Controls | SHA3-256 hash chain + ML-DSA-65 signed entries | β |
| 164.312(c)(1) | Integrity | ML-DSA-65 payload signatures on all PHI operations | β |
| 164.312(d) | Person Authentication | JWT + MFA + FIDO2 WebAuthn | β |
| 164.312(e)(1) | Transmission Security | TLS 1.3 + PQC payload signing | β |