01 · HIPAA Compliance

HIPAA compliance,
explained in English.

Not a legal document. A straight explainer of what HIPAA means for your practice and exactly how Perpetua meets every requirement.

Request a BAARead privacy policy
02 · The Basics

What HIPAA means for your practice.

03 · Safeguards

Every safeguard, how we implement it.

01

Encryption everywhere

AES-256 at rest, TLS 1.3 in transit. Call recordings, transcripts, and database backups all encrypted with separate keys.

02

Role-based access controls

Every user has a role (owner, manager, biller, front desk, provider). Permissions are enforced at the database row level — not just in the UI.

03

Complete audit logs

Every PHI access — view, edit, export, API call — is logged with user, timestamp, IP, and reason. Logs retained 7 years.

04

MFA required

Multi-factor authentication is required for every Perpetua employee and strongly encouraged for your team. We support TOTP and hardware keys.

05

HIPAA-eligible infrastructure

Data stored on Supabase (Postgres) running in AWS us-east under a signed BAA. Row-Level Security prevents cross-tenant data access at the database level.

06

Breach response plan

We monitor for anomalies 24/7. If a breach affects PHI, you're notified within 24 hours of discovery — far faster than HIPAA's 60-day minimum.

04 · Data Minimization

What we store · what we don't.

We only take what's required to run the Service. Everything else stays in your EHR.

Yes

Appointment data

Patient name, appointment time, reason for visit, provider, status.

Yes

Insurance information

Member ID, payer, plan type, copay, deductible status — for eligibility checks.

Yes

Call recordings & transcripts

Stored 12 months by default. Retention is configurable; you can also opt out of storage.

Yes

Audit logs

Every PHI access event, retained 7 years per HIPAA minimum.

No

Credit card numbers

Never. Stripe tokenizes all payment data — we see a last-4 at most.

No

Full medical records

We access only what the agent needs (appointment + insurance). We don't pull clinical notes or labs unless you explicitly enable an agent that needs it.

No

Training data for AI models

PHI is never used to train AI. Our language models run under zero-retention contracts with upstream providers.

05 · Same-day BAA

We sign BAAs same-day.

Our Business Associate Agreement is standard, reasonable, and we don't negotiate the terms — so you don't waste a week in a contract loop. Sign it, return it, and we're live same day.

06 · Related

Supporting documents.

07 · Ready?

Start a practice with HIPAA-first AI.

14-day free trial. Signed BAA in your inbox within an hour.

Start free trialBook a demo