Security you can stake your practice on

HIPAA-compliant by design. SOC 2 Type II certified. Every record encrypted, every access logged, every regulation covered — from day one, on every plan.

HIPAA
SOC 2 Type II
GDPR
HL7 / FHIR

HIPAA isn't a checkbox. It's our foundation.

ClinyPal was designed HIPAA-first — not retrofitted for compliance. Every architectural decision, every feature, every data flow has been built and reviewed with HIPAA requirements in mind.

Signed BAA — included on every plan

A Business Associate Agreement is provided and signed digitally before you process any patient data. No premium tier required.

256-bit AES encryption at rest and in transit

All PHI is encrypted using AES-256 at rest and TLS 1.3 in transit. Keys are rotated automatically and stored in an isolated key management service.

Complete audit trail

Every access, edit, and export of any patient record is timestamped and logged — with user ID, IP address, and action type. Immutable and available for 7 years.

Role-based access control (RBAC)

Clinicians see patient records. Admin staff see billing. Receptionists see schedules. Each role is scoped precisely — no over-permissioning possible.

HIPAA Safeguard Checklist
Administrative SafeguardsCovered
Physical SafeguardsCovered
Technical SafeguardsCovered
Business Associate AgreementIncluded
Breach Notification PolicyActive
Risk Assessment ProgramQuarterly
HITECH Act ComplianceVerified
Need a compliance review?
Our compliance team can walk you through every safeguard on a live call.
Book call

Enterprise-grade security. Every tier.

256-bit AES Encryption

All PHI encrypted at rest and in transit. TLS 1.3 for all data in motion. Encryption keys rotated every 90 days.

Multi-Factor Authentication

2FA enforced on all staff accounts via authenticator app or SMS. SSO integration available on Enterprise plans.

Full Audit Logs

Immutable logs of every record access, edit, export, and login — with user, timestamp, IP, and action. Retained 7 years.

Role-Based Access Control

Granular permissions per user role. Clinicians, admin, billing, reception — each scoped to exactly what they need.

Data Residency Options

Choose where your data lives — US, EU, or AU. Data never transits between regions. GDPR-aligned for European clinics.

Continuous Backups

Real-time database replication with point-in-time recovery up to 30 days. RPO of under 1 minute, RTO under 4 hours.

Infrastructure

Built on infrastructure that never sleeps

99.9%
Uptime SLA
<50ms
API response time
24/7
Threat monitoring
3
Availability zones
Every plan is fully HIPAA-compliant from day one

Security built in, not bolted on — try it free

Start your 30-day free trial and get access to full enterprise-grade security: BAA included, encryption on, audit logs running. Not a watered-down free tier — the full thing, completely free to start.

No credit card · BAA included · Full compliance from day one