Security & HIPAA

HIPAA readiness, verified before claims

The production hosting workspace has HIPAA controls enabled. Provider agreements, exact data paths, and operating safeguards are being verified before Nabrimar publishes a full compliance claim or authorizes PHI use.

Current status: provider and BAA verification in progress. Do not place PHI in the service until your organization receives written authorization for its approved configuration.
Infrastructure

HIPAA controls enabled

Production hosting uses restricted access, encrypted transport, audit capabilities, and private data services.

Agreements

Exact scope matters

Each provider that creates, receives, maintains, or transmits PHI must be included in the approved data flow and covered by the applicable agreement or documented boundary.

Shared responsibility

Configuration and operations

HIPAA readiness also depends on customer access rules, workforce training, risk analysis, retention, incident response, and using only approved integrations.

HIPAA is a United States legal and regulatory framework, not a product certification. Contractual scope and actual operating practices control.