How the platform supports HIPAA-regulated workloads — the BAA process, the safeguards we operate, and the responsibilities we share with you.
Last updated: July 31, 2026
Quick read: Claimaro is built for HIPAA-regulated workloads and operates as a Business Associate. We sign a BAA with every customer whose data includes Protected Health Information, before any PHI is processed. Compliance is shared: we operate the platform safeguards; you operate your organization's side. This page explains both halves.
HIPAA regulates covered entities (health plans, providers, clearinghouses) and their business associates — vendors that create, receive, maintain, or transmit Protected Health Information (PHI) on their behalf.
Healthcare sharing ministries are generally not "health plans" as HIPAA defines them (45 C.F.R. § 160.103), which means HIPAA's rules often do not legally apply to a ministry or its vendors. Plenty of software vendors use that gap to promise less.
We think that's backwards. Your members share medical bills, diagnoses, and family health details with you — the sensitivity of the data doesn't change because the statute's definitions don't reach it. So Claimaro holds ministry data to the same standard as regulated PHI: the same encryption, the same audit logging, the same access controls, and a contractual data-protection agreement with the same substance as a BAA. Your board gets the same answers either way.
The HIPAA Security Rule requires administrative, physical, and technical safeguards. On the platform side, Claimaro operates:
The full control descriptions live on our Security page.
No vendor can make your organization HIPAA compliant by itself — compliance is a property of your program, not of software. Using Claimaro, your side of the model is:
These mirror the customer obligations in the BAA itself, so the contract and this page say the same thing.
The BAA is included on every plan — it is not an enterprise upsell. The sequence:
To request the BAA, our security documentation, or a completed security questionnaire: security@claimaro.com.
No one is — there is no such thing as HIPAA certification. HHS does not certify, endorse, or accredit any software as "HIPAA compliant," and any vendor claiming a HIPAA certificate is overstating what exists. What a serious vendor can do is operate the safeguards the HIPAA Security Rule requires, sign a Business Associate Agreement, and show you the controls. That is what Claimaro does.
Yes. A BAA is included on every plan and is signed alongside your services agreement, before any PHI is processed. It covers permitted uses, safeguards, breach notification timelines, subcontractor obligations, and return or destruction of your data at termination.
Not yet. We operate a control environment aligned to the SOC 2 trust services criteria — security, availability, confidentiality, and processing integrity — and a formal SOC 2 audit is on our roadmap. Documentation of our controls is available to qualified prospects under NDA.
In the United States, on SOC 2 Type II-audited infrastructure providers that support HIPAA workloads under Business Associate Agreements. Every customer's data lives in its own isolated database.
No. We do not use member PHI to train models or for marketing. Aggregated, de-identified data may be used to improve the platform, as described in our Privacy Policy.
Often not directly: healthcare sharing ministries are generally not "health plans" as HIPAA defines them, so HIPAA may not legally attach to your ministry. Claimaro protects your members’ data to the same standard anyway — the same encryption, audit logging, access controls, and a contractual data-protection agreement with the same substance as a BAA.
Note: This page is a plain-English overview, not legal advice — how HIPAA applies to your organization depends on facts about your organization. For procurement, request our current security documentation and subprocessor list at security@claimaro.com.