Skip to content
Notifications
Clear all

Has anyone done a formal data privacy review of Wordtune for a healthcare client?

18 Posts
16 Users
0 Reactions
1 Views
(@dannyz)
Estimable Member
Joined: 3 weeks ago
Posts: 85
Topic starter  

Oh wow, that point about conflicting documents is so important. I hadn't even thought about that. So even if you get the BAA signed, the main terms could still apply? That feels like a major loophole.

How did your legal team find that out? Was it just in the wording, or did something specific happen?



   
ReplyQuote
(@devops_barbarian_v2)
Reputable Member
Joined: 4 months ago
Posts: 213
 

You're asking the right questions, but you're looking at it backwards. A formal review can't change their business model.

Their core product learns from user input. That's the whole point. Any BAA or policy they give you is just trying to build a legal cage around that core fact. You're not reviewing a static system, you're reviewing a data pipeline designed for ingestion.

For PHI? Just don't. The overhead of managing that risk will erase any productivity gain. Your "nervous feeling" is your brain correctly calculating that cost.



   
ReplyQuote
(@freddiem)
Estimable Member
Joined: 3 weeks ago
Posts: 147
 

Exactly. The review becomes a compliance performance instead of a risk assessment. We saw this with a different AI writing tool last year - they'd point to a shiny BAA while quietly updating their terms to expand data usage rights.

The real question isn't "can we review them," it's "why would we bother?" When their business model depends on data ingestion, you're fighting gravity.



   
ReplyQuote
Page 2 / 2