HIPAA Compliance

Curofyxis a reputation-management platform, not a clinical or medical-records system — and that distinction is itself a big part of how we support HIPAA-conscious US clinics. We deliberately don't collect, store, or process Protected Health Information (PHI): no diagnoses, no treatment records, no clinical notes. The only patient data we hold is contact details used to send review requests, and reviews pulled from platforms like Google.

1. What We Don't Handle

By design, Curofyx has a minimal HIPAA footprint because it never touches the data HIPAA is built to protect.

  • No diagnostic, treatment, or clinical record data of any kind
  • No insurance, billing-code, or medical claims data
  • Patient contact details are used exclusively to send and track review requests

2. Administrative Safeguards

The data we do hold is still governed by clear internal policy and role-based access, in line with HIPAA's administrative safeguard requirements.

  • Granular, per-user access permissions — not an all-or-nothing login
  • Every action on a clinic's data (replies posted, requests sent, roles changed, logins) is recorded in a full activity log
  • Access reviewed and revocable by the clinic owner at any time

3. Technical Safeguards

The same technical controls we apply for our UK clinics apply equally to US clinic data.

  • TLS encryption for all data in transit
  • AES-256-GCM encryption for stored platform credentials, bcrypt hashing for passwords
  • Tenant isolation — one clinic's data is never reachable by another, enforced at every API request
  • Rate-limited authentication and automatic account lockout after repeated failed logins

4. Physical Safeguards

Our infrastructure runs on reputable cloud hosting providers, who are responsible for the physical security, access control, and environmental protection of the underlying data centres.

5. Compliance Responsibility

Because Curofyx does not process PHI, it does not typically act as a HIPAA Business Associate. US clinics remain responsible for their own HIPAA compliance for any PHI held in their own clinical systems — Curofyx simply doesn't need, and doesn't ask for, that data.

6. Contact

Email: info@curofyx.com