HIPAA Compliance Overview

    Cura Connection is built from the ground up for HIPAA-sensitive healthcare workflows. This document outlines our approach to protecting patient health information.

    Technical Safeguards

    Our technical safeguards include:

    • All data encrypted in transit using TLS 1.2+
    • All data encrypted at rest using AES-256 encryption
    • Role-based access controls for all system users
    • Comprehensive audit logging for all data access
    • Automatic session timeouts and authentication controls

    Administrative Safeguards

    • Designated Privacy Officer and Security Officer
    • Documented HIPAA policies and procedures governing workforce access to protected health information
    • Workforce HIPAA training required on hire and annually thereafter
    • Documented incident response and breach notification procedures
    • Security risk assessment program covering administrative, physical, and technical safeguards

    Physical Safeguards

    • Cloud infrastructure hosted with a HIPAA-eligible cloud provider under an executed Business Associate Agreement
    • Automated encrypted backups with independent weekly snapshot retention

    Security & Subprocessors

    For our full security posture, subprocessor list, and compliance status, visit our Security & Compliance page.

    Business Associate Agreements

    Cura Connection executes Business Associate Agreements (BAAs) with all healthcare practice clients and all upstream technology vendors that may have access to protected health information.

    We maintain a subprocessor register documenting each vendor, the data they receive, and BAA status. Practices may request this register.

    Patient Consent & Communications

    Patients opt in to SMS communications explicitly, and SMS is off by default until a patient takes action to enable it. Transactional email communications operate on an opt-out basis, consistent with the treatment relationship the practice has already established. Patients may opt out of either at any time. Practices are responsible for obtaining and documenting patient consent at intake; our platform sends communications on the practice's instruction and does not serve as the practice's system of record for clinical consent.

    SMS communications comply with TCPA regulations. Email communications comply with CAN-SPAM requirements.

    Program Status

    Cura Connection maintains documented HIPAA policies and procedures. We are happy to discuss our security posture, provide our subprocessor register, and answer security questionnaires as part of your vendor review process. Reach us through our contact form.

    Contact

    For HIPAA compliance questions, contact our Privacy Officer through our contact form.