HIPAA compliance isn't optional. We know.
Korafy was built for clinical workflows from day one. Here's exactly how we protect your patients' data.
HIPAA Safeguards
All three safeguard categories. Implemented and documented.
Administrative Safeguards
- Designated HIPAA Security Officer
- Workforce training on PHI handling
- Risk assessments conducted quarterly
- Incident response plan in place
- Business Associate Agreements with core infrastructure vendors
Physical Safeguards
- Cloud-hosted — no on-premise servers
- HIPAA-eligible cloud infrastructure with SOC 2 compliance
- Facility access controls via cloud provider
- Workstation use policies enforced
Technical Safeguards
- AES-256 encryption at rest
- TLS 1.3 encryption in transit
- Role-based access control (RBAC)
- Comprehensive audit logging
- Automatic session timeout
- Multi-factor authentication (MFA)
Infrastructure
How your data is stored and protected.
Encrypted Data Storage
All PHI is encrypted at rest using AES-256 and in transit using TLS 1.3. Database backups are encrypted and stored in geographically redundant locations.
HIPAA-Eligible Infrastructure
Korafy runs on HIPAA-eligible cloud infrastructure. We maintain Business Associate Agreements with our core infrastructure providers — AWS (hosting) and Neon (database) — with account-level BAA coverage, eligible services, and configuration under ongoing verification.
Business Associate Agreements
We maintain Business Associate Agreements with our core infrastructure providers, AWS and Neon, and are verifying account-level coverage and configuration. Telnyx, used solely as a fax transmission conduit, does not persist fax documents — we are confirming fax content is not retained in media storage, webhook payloads, logs, or support systems beyond temporary transmission.
Audit Logging
Every access to PHI is logged with timestamp, user identity, and action taken. Logs are immutable and retained for a minimum of 6 years, supporting both HIPAA requirements and practice-level compliance audits.
Compliance Roadmap
Where we are. Where we're going.
HIPAA Administrative, Physical & Technical Safeguards
In ProgressAdministrative, physical, and technical safeguards implemented and documented. Business Associate Agreement verification in progress (see below).
Business Associate Agreements
In ProgressBAAs in place with core infrastructure providers (AWS, Neon); account-level coverage under verification. Telnyx is a transmission conduit only and does not persist fax content — confirmation in progress.
SOC 2 Type I Audit
In ProgressSecurity controls audit underway. Target completion: Q3 2026.
SOC 2 Type II Audit
PlannedContinuous monitoring audit planned for Q1 2027.
Questions about our security? Let's talk.
We're happy to walk through our security posture, sign a BAA, and answer any compliance questions your team has.