Security By Design

Security by design. Built to support HIPAA compliance.
Last Updated: May 23, 2026
Classification: Public Security & Compliance Statement

[04:22:18 UTC] > Initializing Compliance Verification...
[04:22:19 UTC] > Verifying AES-256-GCM Database Encryption at Rest... [SUCCESS]
[04:22:19 UTC] > Checking TLS 1.3 Transport Security Handshakes... [SUCCESS]
[04:22:20 UTC] > Validating Row-Level Tenant Data Isolation Boundaries... [SUCCESS]
System Status: SECURE. Compliance validation complete.

At Clinapse, the privacy, confidentiality, and security of Protected Health Information (PHI) is a top priority. We design and build our platform around established healthcare security and data-privacy practices, and we continue to invest in our compliance program as we grow.

Built to Support HIPAA

Clinapse acts as a Business Associate to the healthcare practices it serves and executes a Business Associate Agreement (BAA) where one is required. Our platform is built to support the federal HIPAA Security and Privacy Rules.

End-to-End Encryption

Sensitive data is encrypted at rest using AES-256-GCM with dynamic key rotation, and encrypted in transit using strict TLS 1.2 or TLS 1.3.

SOC 2 Readiness

We are building our operational procedures and technical controls toward the AICPA Trust Services Criteria. SOC 2 readiness is in progress; Clinapse has not yet completed a SOC 2 audit.

Our Security Controls

To secure patient records, maintain high availability, and protect independent medical practices from cybersecurity threats, Clinapse incorporates best-of-breed infrastructure defenses.