HIPAA Compliance Overview
Cura Connection is built from the ground up for HIPAA-sensitive healthcare workflows. This document outlines our approach to protecting patient health information.
Technical Safeguards
Our technical safeguards include:
- All data encrypted in transit using TLS 1.2+
- All data encrypted at rest using AES-256 encryption
- Role-based access controls for all system users
- Comprehensive audit logging for all data access
- Automatic session timeouts and authentication controls
Administrative Safeguards
- Designated Privacy Officer and Security Officer
- Documented HIPAA policies and procedures governing workforce access to protected health information
- Workforce HIPAA training required on hire and annually thereafter
- Documented incident response and breach notification procedures
- Security risk assessment program covering administrative, physical, and technical safeguards
Physical Safeguards
- Cloud infrastructure hosted with a HIPAA-eligible cloud provider under an executed Business Associate Agreement
- Automated encrypted backups with independent weekly snapshot retention
Security & Subprocessors
For our full security posture, subprocessor list, and compliance status, visit our Security & Compliance page.
Business Associate Agreements
Cura Connection executes Business Associate Agreements (BAAs) with all healthcare practice clients and all upstream technology vendors that may have access to protected health information.
We maintain a subprocessor register documenting each vendor, the data they receive, and BAA status. Practices may request this register.
Patient Consent & Communications
Patients opt in to SMS communications explicitly, and SMS is off by default until a patient takes action to enable it. Transactional email communications operate on an opt-out basis, consistent with the treatment relationship the practice has already established. Patients may opt out of either at any time. Practices are responsible for obtaining and documenting patient consent at intake; our platform sends communications on the practice's instruction and does not serve as the practice's system of record for clinical consent.
SMS communications comply with TCPA regulations. Email communications comply with CAN-SPAM requirements.
Program Status
Cura Connection maintains documented HIPAA policies and procedures. We are happy to discuss our security posture, provide our subprocessor register, and answer security questionnaires as part of your vendor review process. Reach us through our contact form.
Contact
For HIPAA compliance questions, contact our Privacy Officer through our contact form.