How Medoura Handles HIPAA
There's no such thing as being "HIPAA certified" — no agency issues that stamp, and any platform that implies otherwise is telling you something's off. What we can do is show you exactly what's in place, control by control, and what's still yours to own as the covered entity. That's this page.
Administrative Safeguards
45 CFR §164.308
Role-based access control — staff only see what their role requires.
Continuous monitoring plus a breach-notification commitment — see our Notice of Privacy Practices.
Every practice signs a BAA with Medoura before patient data goes live.
Physical Safeguards
45 CFR §164.310
Patient data lives in audited cloud infrastructure, not physical servers you have to secure yourself.
Inherited from our cloud infrastructure providers' own audited physical security controls.
Technical Safeguards
45 CFR §164.312
Unique staff logins plus mandatory multi-factor authentication — not a toggle, not optional.
Every access to patient data is logged in an append-only trail — who, what, and when.
The audit log itself can't be edited or deleted, even by staff with admin access.
All data in transit is encrypted via TLS.
Patient data is encrypted at rest at the infrastructure level.
Privacy Rule & Breach Notification
45 CFR §164.520, §164.400–414
A real, published notice describing patients' rights over their data.
Medoura commits to notifying affected practices promptly if a breach occurs.
Patients can submit — or staff can log on their behalf — requests to access, amend, or restrict use of their records. Medoura tracks response deadlines and flags overdue requests; your practice is responsible for fulfilling them.
HIPAA does not include a right to deletion or erasure (unlike GDPR/CCPA). Medoura's own retention safeguards block deleting a record while a request is open, but this does not create a right to be forgotten.
Operational Resilience
Patient data can be restored to any point within the backup window if something goes wrong.
How We Respond to a Security Incident
If a security incident is detected, our process is to contain it, determine scope and impact, and notify affected practices without unreasonable delay — consistent with our contractual commitment to notify within ten (10) business days of discovery.
Subprocessors
A small number of vetted subprocessors handle specific functions: database & hosting, payment processing, transactional email, and error monitoring — each under contractual data-protection obligations. The full list, including specific vendor names, is available to every practice in their staff portal after signing the NDA in their legal docs.
What's Still on You
HIPAA compliance is a shared responsibility. Medoura covers the platform — your practice owns the rest.
The Honest Picture
- Our multi-tenant data isolation is under continuous, independent review. When review surfaces an issue, we fix it and harden against it — that's an ongoing process, not a one-time guarantee of perfection.
Questions about our compliance posture, or need a copy of your BAA? Reach us at hello@cofabri.com.