HIPAA compliance is available for Enterprise customers after Exa enables it for your team. Contact sales@exa.ai to discuss Enterprise access, BAA requirements, and enablement.
compliance field:
403 FEATURE_DISABLED.
HIPAA mode includes Zero Data Retention for those requests: Exa does not persist PHI.
Supported endpoints
Thecompliance field is recognized on:
Other endpoints reject the field.
Requirements
HIPAA mode supports cached retrieval only. Compatible requests:- On
/search, settypetoinstantorfast - Request
textorhighlights(notsummary) - Use cache-only content: omit freshness fields, or set
maxAgeHours: -1on/contents
400 INVALID_REQUEST_BODY, including:
summaryon/contents, orcontents.summaryon/search- Freshness settings that require a live fetch, such as
maxAgeHours: 0or a positivemaxAgeHours - Search requests that omit
type, or use a type other thaninstantorfast