Last updated August 8, 2026
ClinyPal is built with the safeguards a HIPAA-covered entity needs from its software vendor. This page summarizes how those safeguards work in practice.
We execute a Business Associate Agreement (BAA) with covered entities that request one, formalizing our obligations as a business associate handling protected health information (PHI) on their behalf.
Every account is tied to an individual login with role-based permissions (admin and staff tiers), so access to PHI is limited to what a given role actually needs.
Every view, download, print, and edit of patient data is logged automatically to an audit trail, satisfying the audit-control requirement of the HIPAA Security Rule. See Security.
Data is encrypted in transit (TLS) and at rest. Sensitive integration credentials are separately encrypted rather than stored in plain text.
Two-factor authentication and passkey login are available on every account, reducing the risk of credential-based unauthorized access. See Security.
HIPAA compliance is a shared responsibility. ClinyPal provides the technical and administrative safeguards described here; the covered entity remains responsible for its own workforce training, physical safeguards, and appropriate use of the platform.