Curofyxis a reputation-management platform, not a clinical or medical-records system — and that distinction is itself a big part of how we support HIPAA-conscious US clinics. We deliberately don't collect, store, or process Protected Health Information (PHI): no diagnoses, no treatment records, no clinical notes. The only patient data we hold is contact details used to send review requests, and reviews pulled from platforms like Google.
By design, Curofyx has a minimal HIPAA footprint because it never touches the data HIPAA is built to protect.
The data we do hold is still governed by clear internal policy and role-based access, in line with HIPAA's administrative safeguard requirements.
The same technical controls we apply for our UK clinics apply equally to US clinic data.
Our infrastructure runs on reputable cloud hosting providers, who are responsible for the physical security, access control, and environmental protection of the underlying data centres.
Because Curofyx does not process PHI, it does not typically act as a HIPAA Business Associate. US clinics remain responsible for their own HIPAA compliance for any PHI held in their own clinical systems — Curofyx simply doesn't need, and doesn't ask for, that data.
Email: info@curofyx.com