How Medoura Handles HIPAA

There's no such thing as being "HIPAA certified" — no agency issues that stamp, and any platform that implies otherwise is telling you something's off. What we can do is show you exactly what's in place, control by control, and what's still yours to own as the covered entity. That's this page.

Compliance StatusAll Controls Active
13
Controls Verified
4
Safeguard Categories

Administrative Safeguards

45 CFR §164.308

Workforce access managementVERIFIED

Role-based access control — staff only see what their role requires.

Security incident proceduresVERIFIED

Continuous monitoring plus a breach-notification commitment — see our Notice of Privacy Practices.

Business Associate AgreementVERIFIED

Every practice signs a BAA with Medoura before patient data goes live.

Physical Safeguards

45 CFR §164.310

No on-premises PHI serversVERIFIED

Patient data lives in audited cloud infrastructure, not physical servers you have to secure yourself.

Data center controlsVERIFIED

Inherited from our cloud infrastructure providers' own audited physical security controls.

Technical Safeguards

45 CFR §164.312

Access controlVERIFIED

Unique staff logins plus mandatory multi-factor authentication — not a toggle, not optional.

Audit controlsVERIFIED

Every access to patient data is logged in an append-only trail — who, what, and when.

Integrity controlsVERIFIED

The audit log itself can't be edited or deleted, even by staff with admin access.

Transmission securityVERIFIED

All data in transit is encrypted via TLS.

Encryption at restVERIFIED

Patient data is encrypted at rest at the infrastructure level.

Privacy Rule & Breach Notification

45 CFR §164.520, §164.400–414

Notice of Privacy PracticesVERIFIED

A real, published notice describing patients' rights over their data.

Breach notification commitmentVERIFIED

Medoura commits to notifying affected practices promptly if a breach occurs.

Patient data request handlingVERIFIED

Patients can submit — or staff can log on their behalf — requests to access, amend, or restrict use of their records. Medoura tracks response deadlines and flags overdue requests; your practice is responsible for fulfilling them.

HIPAA does not include a right to deletion or erasure (unlike GDPR/CCPA). Medoura's own retention safeguards block deleting a record while a request is open, but this does not create a right to be forgotten.

Operational Resilience

Automated backups & point-in-time recoveryVERIFIED

Patient data can be restored to any point within the backup window if something goes wrong.

How We Respond to a Security Incident

If a security incident is detected, our process is to contain it, determine scope and impact, and notify affected practices without unreasonable delay — consistent with our contractual commitment to notify within ten (10) business days of discovery.

Subprocessors

A small number of vetted subprocessors handle specific functions: database & hosting, payment processing, transactional email, and error monitoring — each under contractual data-protection obligations. The full list, including specific vendor names, is available to every practice in their staff portal after signing the NDA in their legal docs.

What's Still on You

HIPAA compliance is a shared responsibility. Medoura covers the platform — your practice owns the rest.

Account hygiene for your own staff — no shared logins, and offboard access promptly when someone leaves.
Assigning least-privilege roles so staff only get the access their job requires.
Securing the devices and networks your team uses to access Medoura.
Complying with state-level privacy requirements beyond HIPAA where they apply to your practice.
Reviewing and executing your BAA with Medoura at onboarding.
Responding to and fulfilling patient data requests within the tracked deadlines — Medoura surfaces overdue items, but does not respond on your behalf.

The Honest Picture

  • Our multi-tenant data isolation is under continuous, independent review. When review surfaces an issue, we fix it and harden against it — that's an ongoing process, not a one-time guarantee of perfection.

Questions about our compliance posture, or need a copy of your BAA? Reach us at hello@cofabri.com.