HIPAA compliance isn't optional. We know.

Korafy was built for clinical workflows from day one. Here's exactly how we protect your patients' data.

HIPAA Safeguards

All three safeguard categories. Implemented and documented.

Administrative Safeguards

  • Designated HIPAA Security Officer
  • Workforce training on PHI handling
  • Risk assessments conducted quarterly
  • Incident response plan in place
  • Business Associate Agreements with core infrastructure vendors

Physical Safeguards

  • Cloud-hosted — no on-premise servers
  • HIPAA-eligible cloud infrastructure with SOC 2 compliance
  • Facility access controls via cloud provider
  • Workstation use policies enforced

Technical Safeguards

  • AES-256 encryption at rest
  • TLS 1.3 encryption in transit
  • Role-based access control (RBAC)
  • Comprehensive audit logging
  • Automatic session timeout
  • Multi-factor authentication (MFA)

Infrastructure

How your data is stored and protected.

Encrypted Data Storage

All PHI is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted and stored in geographically redundant locations.

HIPAA-Eligible Infrastructure

Korafy runs on HIPAA-eligible cloud infrastructure. We maintain Business Associate Agreements with our core infrastructure providers — AWS (hosting) and Neon (database) — with account-level BAA coverage, eligible services, and configuration under ongoing verification.

Business Associate Agreements

We maintain Business Associate Agreements with our core infrastructure providers, AWS and Neon, and are verifying account-level coverage and configuration. Telnyx, used solely as a fax transmission conduit, does not persist fax documents — we are confirming fax content is not retained in media storage, webhook payloads, logs, or support systems beyond temporary transmission.

Audit Logging

Every access to PHI is logged with timestamp, user identity, and action taken. Logs are immutable and retained for a minimum of 6 years, supporting both HIPAA requirements and practice-level compliance audits.

Compliance Roadmap

Where we are. Where we're going.

HIPAA Administrative, Physical & Technical Safeguards

In Progress

Administrative, physical, and technical safeguards implemented and documented. Business Associate Agreement verification in progress (see below).

Business Associate Agreements

In Progress

BAAs in place with core infrastructure providers (AWS, Neon); account-level coverage under verification. Telnyx is a transmission conduit only and does not persist fax content — confirmation in progress.

SOC 2 Type I Audit

In Progress

Security controls audit underway. Target completion: Q3 2026.

SOC 2 Type II Audit

Planned

Continuous monitoring audit planned for Q1 2027.

Questions about our security? Let's talk.

We're happy to walk through our security posture, sign a BAA, and answer any compliance questions your team has.