top of page


Can the US government access my patient data?

  • Writer: Sherwin Gaddis
    Sherwin Gaddis
  • Jul 4
  • 5 min read

"If your EHR vendor disappeared tomorrow, could you recover every patient record without asking their permission?"


How to Own Your Patient Data and Keep It Out of AI Training


Data sovereignty in a cloud EHR comes in two layers. The contractual layer: your organization owns the data, and the vendor is legally barred from de-identifying, commercializing, or using it to train AI or ML models.


The architectural layer: the cloud infrastructure runs in an account you own and control. Every Tarevo customer gets the contractual layer. Any Tarevo customer who wants the architectural layer gets it by default; we deploy OpenEMR into an AWS account owned by your organization.


Almost no cloud EHR vendor offers either layer honestly. We offer both.


data belongs to the client not the EHR company

If you’ve read this far, you’re probably an administrator, compliance officer, or medical director asking a specific question:


“How do I move to a modern cloud EHR without handing my patient data to a vendor who might monetize it, feed it to AI training, or lock me into their infrastructure?”


You’re right to be asking. Here’s the answer.


What “data sovereignty” actually means for an EHR


The phrase gets used loosely. Most cloud EHR vendors will tell you that your data is “yours” and that they’re HIPAA-compliant. Both of those statements can be true while the vendor still:


  • Stores your data in their cloud account, where their operations team has default administrative access

  • Reserves the right to de-identify and aggregate your data for “product improvement,” “benchmarking,” or “research”

  • Uses your patient data — de-identified or otherwise — to train internal AI/ML systems

  • Retains custody of your database after termination and negotiates the terms of your exit


None of that is illegal. It is, however, incompatible with the kind of data control that tribal health organizations, FQHCs, community health centers, and any privacy-serious enterprise clinic actually need.


True data sovereignty rests on four commitments:


  1. The legal terms are unambiguous. A signed agreement — Business Associate Agreement plus any addendum you require that prohibits secondary use, commercial use, de-identification-for-resale, and AI/ML training on your patient data.

  2. The personnel are accountable. US-based staff for any PHI access, with named individuals and revocable credentials.

  3. The vendor’s access is delegated and revocable. Not the vendor sitting on top of your data with default admin. A scoped role you can withdraw at any time.

  4. The infrastructure architecture matches your comfort level. For organizations that want the strongest possible separation, the cloud account itself is in your name — root credentials, encryption keys, everything.


Commitments 1 through 3 apply to every Tarevo customer. Commitment 4 is your choice.


The universal Tarevo commitment (every customer, no exceptions)


Regardless of which deployment model you choose, we make three legally binding commitments to every clinical customer:


  • We do not sell, share, or license your patient data. Not to marketers. Not to research organizations. Not to health systems. Not to anyone.

  • We do not train AI or ML models on your patient data. Not our own models. Not third-party models. Not de-identified. Not aggregated.

  • The data belongs to you. Tarevo has no rights to it — not for “product improvement,” not for “benchmarking,” not for anything. If you leave Tarevo, the data leaves with you.


We sign these commitments in the BAA. When customers bring their own data sovereignty addenda from tribal health organizations, from FQHCs, from community health centers, from any organization with specific requirements, we sign those too.


Recent customer-supplied addenda we’ve signed include clauses that:


  • Prohibit the de-identification of patient data for any purpose

  • Prohibit secondary or commercial use by Tarevo or any subcontractor

  • Prohibit training of AI or ML systems — internal or third-party — on customer data

  • Affirm indigenous or organizational ownership of the data

  • Mandate US data residency for storage and processing

  • Require US-based personnel for any PHI access

  • Preserve the customer’s right to audit and withdraw access at any time


Bring your requirements. If we can sign, we do. If we can’t, we tell you why up front.


Two deployment models — you choose


Model 1 (default): Customer-owned AWS account on VPS

The strongest possible sovereignty posture. You create an AWS account under your organization’s name. You are the account owner. You hold the root credentials and the master encryption keys.


Tarevo gets a scoped IAM role, a specific, auditable, revocable administrative pathway that lets us build, deploy, monitor, and maintain your OpenEMR environment. You can revoke that role at any time, without our cooperation, and our access dies instantly. Nothing on our side has a backdoor.

This is our default deployment for tribal health organizations, FQHCs, and any customer whose legal counsel, compliance officer, or leadership team wants the architecture to reinforce the contract. Architectural incapacity, backed by contractual prohibition, even if a future Tarevo wanted to misuse your data, this deployment model would prevent it.


Model 2 (optional): Tarevo-managed AWS account with our Fargate self-healing elastic solution


For customers who prefer a simpler operational model — one less AWS account to administer, no root credentials to secure on your side — we also deploy into a Tarevo-managed AWS account. The same universal contractual commitments apply: we don’t sell, share, or train AI/ML on your data, and the data belongs to you.


The tradeoff is transparent: contractual sovereignty is the same; architectural separation is not as strong. This model works well for smaller practices without dedicated IT or compliance staff who want fewer moving parts.


Compute scales from 2 to 100+ tasks automatically. Data is encrypted in transit and at rest. Backups run daily, weekly, and monthly with 7-year retention. Multi-zone redundancy keeps clinical operations running through data center failures.


We share the vision of our clients

The AI/ML training question, specifically


In 2026, the question every clinic should ask a prospective EHR vendor is:

“Are you using our patient data — de-identified or otherwise — to train any AI or ML system? Will you sign a legal document prohibiting it?”


Most cloud EHR vendors have not answered this question directly. Some have privately begun using aggregated customer data for model training. Some reserve the right in their Terms of Service. Some have already licensed data to third parties.


Tarevo’s position is straightforward. We do not train AI or ML models on customer patient data. Not our own models. Not third party models. Not de-identified. Not aggregated. We will sign a legally binding prohibition to that effect for any customer who requires it in writing. We do not sell, share, or license customer data to anyone.


Why most cloud EHRs cannot offer this:


The economics of most cloud EHRs depend on the vendor owning the hosting environment. It’s cheaper for them to run one large multi-tenant deployment than to build separate customer-owned environments. Multi-tenancy also lets them claim aggregated data as their own; the fine print in most vendor contracts assigns that right to the vendor.


Tarevo’s architecture is deliberately more expensive to operate on our side. Each customer gets a dedicated AWS account and a dedicated environment. We charge for the engineering and stewardship required to run that. But the result is an architecture that structurally cannot do the things privacy-serious customers are (rightly) worried about.


If you are a tribal health organization, an FQHC, a community health center, or any private practice that takes patient data ownership seriously, that architectural difference is what you’re paying for.


Ready to talk about your requirements?


If your organization has specific data sovereignty requirements tribal, legal, denominational, or organizational, we want to see

them before we quote anything. Bring your addendum. Bring your compliance officer. Bring your attorney.

We’ll tell you honestly whether we can meet the terms. If we can, we sign. If we can’t, we tell you why. That’s the conversation.


Schedule a Strategy Meeting for 30 minutes, no commitment, technical and business questions welcome.


Tarevo’s mission: building wealth for doctors in private practice. Reach Sherwin at sherwin@tarevo.com or 757-328-2736


We should meet because we have a shared vision

Comments


bottom of page