HIPAA

HIPAA at Claimaro

How the platform supports HIPAA-regulated workloads — the BAA process, the safeguards we operate, and the responsibilities we share with you.

Last updated: July 31, 2026

Quick read: Claimaro is built for HIPAA-regulated workloads and operates as a Business Associate. We sign a BAA with every customer whose data includes Protected Health Information, before any PHI is processed. Compliance is shared: we operate the platform safeguards; you operate your organization's side. This page explains both halves.

1. How HIPAA applies to Claimaro — and to you

HIPAA regulates covered entities (health plans, providers, clearinghouses) and their business associates — vendors that create, receive, maintain, or transmit Protected Health Information (PHI) on their behalf.

  • If you run a self-funded health plan, your plan is typically a covered entity. Claimaro acts as your Business Associate, and we sign a BAA with you directly.
  • If you are a TPA administering plans for others, you are typically a business associate of your upstream clients. Claimaro then acts as your subcontractor under HIPAA, and our BAA passes your obligations through to us, as § 164.502(e) requires.
  • If you are a healthcare sharing ministry, HIPAA often does not attach to you at all — see Section 2, because this surprises most operators.

2. A plain-English note for healthcare sharing ministries

Healthcare sharing ministries are generally not "health plans" as HIPAA defines them (45 C.F.R. § 160.103), which means HIPAA's rules often do not legally apply to a ministry or its vendors. Plenty of software vendors use that gap to promise less.

We think that's backwards. Your members share medical bills, diagnoses, and family health details with you — the sensitivity of the data doesn't change because the statute's definitions don't reach it. So Claimaro holds ministry data to the same standard as regulated PHI: the same encryption, the same audit logging, the same access controls, and a contractual data-protection agreement with the same substance as a BAA. Your board gets the same answers either way.

3. What Claimaro provides

The HIPAA Security Rule requires administrative, physical, and technical safeguards. On the platform side, Claimaro operates:

  • Encryption — TLS 1.2+ in transit, AES-256 at rest, for all customer data including PHI, files, and backups.
  • Access control — role-based access with seven system roles enforced server-side, TOTP multi-factor authentication with customer-controlled enforcement, and automatic session termination.
  • Tenant isolation — every customer runs on its own isolated database, with application-layer tenant scoping and Row Level Security as a backstop.
  • Audit logging — every authenticated action touching PHI is recorded in an append-only audit log retained for at least six years, with automated anomaly detection over audit events.
  • PII masking — highly sensitive fields (SSN, government ID, full DOB) are masked by default; reveal actions are logged with the user, timestamp, and reason.
  • Controlled staff access — Claimaro staff access to your tenant is time-boxed, logged in both our cross-tenant audit trail and your own audit log, and you can disable it entirely.
  • Vetted infrastructure — SOC 2 Type II-audited hosting and database providers that support HIPAA workloads under Business Associate Agreements, in U.S. regions. Every subprocessor that may access PHI is engaged under a BAA before any PHI is processed.
  • Breach notification — a documented incident response plan, with customer notification without unreasonable delay and within the timelines required by HIPAA and your BAA.

The full control descriptions live on our Security page.

4. What you're responsible for

No vendor can make your organization HIPAA compliant by itself — compliance is a property of your program, not of software. Using Claimaro, your side of the model is:

  • Access decisions — you assign roles, provision and deprovision your users, and decide who in your organization can see what.
  • Authentication policy — you enforce MFA for your staff (the platform gives you the toggle; turning it on is your call).
  • Workforce training — you train your people on HIPAA privacy and appropriate handling of member data.
  • Your own policies — your notice of privacy practices, your designated privacy/security officer, your risk assessments, and any member-facing obligations under § 164.524–528 (access, amendment, accounting) — the platform gives you the records and export tools to answer them.
  • Prompt reporting — you tell us quickly if you suspect an account compromise or misuse, so we can act on it.

These mirror the customer obligations in the BAA itself, so the contract and this page say the same thing.

5. The BAA process

The BAA is included on every plan — it is not an enterprise upsell. The sequence:

  1. You sign the services agreement and the BAA together, before any PHI is loaded.
  2. The BAA sets out permitted uses, safeguards, breach notification timelines, subcontractor flow-down, and your audit rights.
  3. At termination, you elect return or destruction of PHI. Because each customer runs on its own isolated database, a complete export of your data is straightforward — your data is never entangled with anyone else's.

To request the BAA, our security documentation, or a completed security questionnaire: security@claimaro.com.

6. Frequently asked questions

Is Claimaro HIPAA certified?

No one is — there is no such thing as HIPAA certification. HHS does not certify, endorse, or accredit any software as "HIPAA compliant," and any vendor claiming a HIPAA certificate is overstating what exists. What a serious vendor can do is operate the safeguards the HIPAA Security Rule requires, sign a Business Associate Agreement, and show you the controls. That is what Claimaro does.

Does Claimaro sign a Business Associate Agreement?

Yes. A BAA is included on every plan and is signed alongside your services agreement, before any PHI is processed. It covers permitted uses, safeguards, breach notification timelines, subcontractor obligations, and return or destruction of your data at termination.

Is Claimaro SOC 2 certified?

Not yet. We operate a control environment aligned to the SOC 2 trust services criteria — security, availability, confidentiality, and processing integrity — and a formal SOC 2 audit is on our roadmap. Documentation of our controls is available to qualified prospects under NDA.

Where is my data hosted?

In the United States, on SOC 2 Type II-audited infrastructure providers that support HIPAA workloads under Business Associate Agreements. Every customer's data lives in its own isolated database.

Does Claimaro use PHI to train AI models?

No. We do not use member PHI to train models or for marketing. Aggregated, de-identified data may be used to improve the platform, as described in our Privacy Policy.

My organization is a healthcare sharing ministry — does HIPAA even apply to us?

Often not directly: healthcare sharing ministries are generally not "health plans" as HIPAA defines them, so HIPAA may not legally attach to your ministry. Claimaro protects your members’ data to the same standard anyway — the same encryption, audit logging, access controls, and a contractual data-protection agreement with the same substance as a BAA.

Note: This page is a plain-English overview, not legal advice — how HIPAA applies to your organization depends on facts about your organization. For procurement, request our current security documentation and subprocessor list at security@claimaro.com.