Compliance

HIPAA & Data Protection Policy

Effective date: May 16, 2026

AI Dominion Consultant and/or J. Johnson & Associates, LLC (“Company,” “we,” “our,” or “us”) fully recognizes the critical importance of protecting Protected Health Information (“PHI”), sensitive personal information, confidential records, and healthcare-related data wherever applicable across our operations.

This comprehensive HIPAA & Data Protection Policy describes our general approach to privacy, security, data protection, AI systems, and healthcare-related technology services that may involve HIPAA-sensitive environments, healthcare-related workflows, regulated operational systems, or related sensitive business contexts.

1. Commitment to Privacy, Security & Data Protection

AI Dominion Consultant implements commercially reasonable administrative, technical, organizational, operational, and physical safeguards thoughtfully designed to support the protection, confidentiality, integrity, and overall security of sensitive information handled in connection with authorized healthcare-related projects, automation systems, CRM environments, communications, intake systems, AI-powered workflows, and related Services.

Security and privacy measures may include, but are not limited to:

  • encrypted communications
  • access controls
  • password protections
  • role-based permissions
  • authentication procedures
  • secure integrations
  • monitoring systems
  • audit logging
  • restricted access environments
  • vendor reviews
  • operational safeguards
  • commercially reasonable cybersecurity practices

2. Scope of Services

This Policy applies wherever AI Dominion Consultant provides or supports Services involving any of the following:

  • healthcare-related automation systems
  • HIPAA-sensitive workflows
  • digital intake systems
  • CRM platforms
  • secure communication systems
  • appointment scheduling systems
  • AI-powered operational workflows
  • secure form collection
  • client engagement systems
  • reporting dashboards
  • workflow automations
  • integrated business platforms
  • third-party healthcare-related technologies
  • operational consulting involving sensitive information

3. Limited HIPAA Role & No Medical Services

AI Dominion Consultant is strictly a technology consulting, automation, implementation, and business solutions provider, and is not any of the following:

  • a healthcare provider
  • medical practice
  • insurance company
  • health plan
  • medical facility
  • licensed medical organization

AI Dominion Consultant does not provide medical advice, healthcare treatment, clinical services, legal advice, compliance certifications, or any form of regulatory guarantees whatsoever.

Clients remain solely and entirely responsible for:

  • determining HIPAA applicability
  • maintaining HIPAA compliance programs
  • ensuring lawful use of systems
  • managing patient communications
  • obtaining required consents and authorizations
  • maintaining internal compliance procedures
  • evaluating regulatory obligations
  • executing Business Associate Agreements (“BAAs”) where applicable
  • verifying their own compliance with federal, state, local, and industry regulations

4. Authorized Access & Confidentiality

Access to sensitive information, systems, records, workflows, communications, automations, and related operational environments shall be strictly limited to authorized personnel, approved vendors, authorized service providers, contractors, or third-party platforms with a clearly legitimate business or operational purpose.

AI Dominion Consultant uses commercially reasonable efforts to maintain confidentiality regarding all of the following:

  • PHI
  • client records
  • operational data
  • healthcare-related workflows
  • automation systems
  • communications
  • credentials
  • integrations
  • proprietary business information

Unauthorized access, misuse, disclosure, copying, transmission, or exploitation of any sensitive information is strictly prohibited and may result in immediate action.

5. AI Systems & Automated Technologies

AI Dominion Consultant may utilize AI-powered technologies, automation systems, machine learning systems, chatbots, virtual assistants, analytics systems, workflow automations, and various third-party AI providers in connection with certain Services we deliver.

AI-assisted systems may support any of the following functions:

  • operational workflows
  • appointment reminders
  • communications
  • reporting
  • intake processes
  • automation tasks
  • analytics
  • administrative support
  • customer engagement

Clients expressly acknowledge that:

  • AI-generated outputs may require human review
  • AI systems may contain inaccuracies or operational limitations
  • third-party AI providers may process or store information
  • AI technologies cannot guarantee error-free performance or full regulatory compliance

Clients remain fully responsible for evaluating the appropriateness of AI systems for their intended use case and regulatory environment.

6. Third-Party Platforms & Service Providers

AI Dominion Consultant may utilize a variety of third-party providers, including but not limited to:

  • CRM platforms
  • cloud hosting providers
  • communication providers
  • AI platforms
  • analytics providers
  • automation systems
  • software vendors
  • payment processors
  • scheduling systems
  • integration providers

Third-party platforms may process, host, transmit, analyze, or store information necessary to facilitate timely service delivery.

AI Dominion Consultant does not own or control any third-party providers and therefore cannot guarantee the independent compliance status, operational reliability, privacy practices, cybersecurity measures, uptime, or overall regulatory posture of external platforms not directly controlled by the Company.

Clients acknowledge that the use of third-party technologies may be subject to separate terms, privacy policies, compliance obligations, and operational limitations independently maintained by those providers.

7. Cybersecurity & Electronic Risks

Despite the commercially reasonable safeguards and security measures implemented by AI Dominion Consultant, no method of transmission over the internet, cloud platform, AI system, software environment, electronic communication, or electronic storage system can ever be guaranteed to be completely secure, uninterrupted, or fully free from unauthorized access, cyber threats, technical failures, or unexpected operational disruptions.

Users acknowledge and willingly accept the inherent risks associated with internet-based communications, cloud technologies, third-party platforms, AI-powered systems, electronic data transmission, and digital storage environments of every kind.

8. Data Retention

AI Dominion Consultant may retain operational records, communications, system logs, workflow records, CRM data, audit logs, integration records, and related business information for as long as reasonably necessary to provide Services, maintain operations, support ongoing system functionality, comply with legal obligations, enforce agreements, resolve disputes, maintain security, and protect legal rights.

Retention periods may vary considerably depending on operational, legal, contractual, and regulatory requirements applicable at the time.

9. Incident Reporting & Security Concerns

Any suspected privacy incidents, unauthorized access, cybersecurity concerns, misuse of systems, data breaches, credential compromises, and operational security concerns should be reported promptly to AI Dominion Consultant using the contact information provided below in this Policy.

AI Dominion Consultant expressly reserves the right to investigate security incidents, restrict access, suspend systems, implement corrective measures, cooperate with legal authorities, and take any commercially reasonable actions necessary to protect systems, data, operations, or users.

10. Compliance Responsibilities

Clients and users remain solely responsible for ensuring full compliance with all applicable:

  • HIPAA requirements
  • healthcare regulations
  • privacy laws
  • security obligations
  • record retention requirements
  • patient communication laws
  • industry standards
  • contractual obligations
  • operational policies

AI Dominion Consultant does not guarantee regulatory compliance, legal sufficiency, certification status, or audit outcomes unless expressly and clearly stated in a separate written agreement executed by authorized representatives of the Company.

11. Dispute Resolution

Any and all disputes arising under or relating to this Policy shall be governed by the dispute resolution, arbitration, governing law, and jurisdiction provisions contained in the applicable Terms & Conditions or governing service agreement of AI Dominion Consultant.

12. Governing Law

This Policy and any disputes arising out of or relating to the Services shall be governed by and construed in accordance with the laws of the State of Texas, without regard to its conflict of law principles.

13. Contact Information

For questions, concerns, or requests relating to this HIPAA & Data Protection Policy, please contact us directly:

AI Dominion Consultant

Email: hello@ffsscenter.org