Security & Compliance

    Cura Connection is designed for healthcare workflows that handle sensitive patient information. This page describes our security, access, and compliance posture. For detailed HIPAA practices, see our HIPAA Compliance Overview.

    Data Encryption

    In transit: All connections use TLS 1.2 or higher. HTTP requests are redirected to HTTPS, database connections require SSL, and object storage denies any non-TLS request.

    At rest: All stores containing protected health information — including our primary database, document storage, and secrets management — are encrypted using customer-managed AWS KMS keys rather than default provider keys.

    Key management: Encryption keys are customer-managed through AWS Key Management Service with automatic key rotation enabled.

    Access Controls

    Authentication: Multi-factor authentication is required for all users. It is not optional.

    Authorization: Role-based access control governs what each user can reach.

    Tenant isolation: Every request is checked against the requesting user's practice before any database query executes, enforced through a single shared code path used across all scoped API routes and covered by automated regression tests.

    Sessions: Sessions expire after 12 hours of inactivity and require full re-authentication with MFA.

    Audit logging: Logins, logouts, MFA events, unauthorized access attempts, and all record creation, modification, deletion, export, and import events are logged.

    Infrastructure

    Hosted on Amazon Web Services in a United States region under an executed Business Associate Agreement. Databases run in private subnets and are not publicly accessible. Automated encrypted backups run daily, with an independent weekly snapshot job retained for twelve weeks. Infrastructure alerting covers application errors, load balancer health, and database resource pressure.

    Compliance Status

    HIPAA: Cura Connection operates as a Business Associate. We execute Business Associate Agreements with healthcare clients and with upstream vendors that handle protected health information, including our cloud infrastructure provider. We maintain documented HIPAA policies and procedures covering administrative, physical, and technical safeguards. Read our HIPAA Compliance Overview.

    SOC 2: We have not completed a SOC 2 audit at this time. Practices requiring formal audit documentation should contact us to discuss timelines.

    Subprocessors

    • Amazon Web Services — cloud hosting, database, document storage, authentication, email delivery, and secrets management. Receives protected health information. Business Associate Agreement executed.
    • Twilio — SMS delivery. Our SMS templates contain no patient name, procedure, or appointment detail; messages carry a phone number and a generic notice directing the patient to secure channels.
    • Anthropic — AI-assisted suggestions during practice onboarding, operating only on publicly available business information. No patient data is sent to this service.

    We use no third-party error tracking or application monitoring vendors. Practices may request our full subprocessor register.

    Questions?

    If you have questions about security, compliance, or would like to review our policies, contact us through our contact form.

    View HIPAA Compliance Overview