Skip to content
HIPAA-Aligned Platform

Your Health Information, Always Protected

Heyzl is fully HIPAA-compliant. Every piece of your protected health information is encrypted, access-controlled, and handled according to the strictest federal standards.

HIPAA-Aligned
SOC 2 (In Progress)
256-bit SSL
GDPR Ready
ISO 27001 (In Progress)

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law that sets national standards for the protection of individually identifiable health information, known as Protected Health Information (PHI).

Any platform that handles, stores, or transmits PHI must comply with HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule — or face civil and criminal penalties.

What counts as PHI?

  • Names and contact information
  • Dates of service or birth
  • Medical record numbers
  • Diagnosis and treatment information
  • Prescription and lab results
  • Health plan beneficiary numbers
  • IP addresses linked to health data
  • Biometric identifiers

How Heyzl Ensures HIPAA Compliance

End-to-End Encryption

All PHI is encrypted at rest (AES-256) and in transit (TLS 1.3). Your medical records and communications are never accessible in plaintext.

Access Controls

Role-based access control (RBAC) ensures only authorized personnel can view PHI. All access is logged and auditable.

Business Associate Agreements

We execute BAAs with all service providers who handle PHI, and offer BAAs to healthcare providers using our platform.

Breach Notification

Robust incident response procedures ensure any breach is identified, contained, and reported within HIPAA's 60-day notification window.

Regular Risk Assessments

We conduct annual HIPAA risk assessments and third-party security audits to identify and remediate vulnerabilities.

Employee Training

All staff complete mandatory HIPAA privacy and security training annually, with role-specific modules for technical and clinical staff.

Need a Business Associate Agreement?

Healthcare providers and covered entities using Heyzl can request a signed BAA. Our legal team typically responds within 2 business days.

Common HIPAA Questions

Heyzl a covered entity or business associate?

Heyzl operates as a business associate under HIPAA. We act as a technology facilitator between patients and covered healthcare providers. We execute BAAs with all providers on our platform.

Where is PHI stored?

Your records are stored in encrypted, US-based data centers with encrypted backups. Because we connect you with international providers, any records you choose to share are transferred to and handled by those providers with your consent and under applicable contractual and technical safeguards.

Can patients access and delete their PHI?

Yes. Patients have full rights of access, amendment, and deletion under HIPAA's Privacy Rule. These controls are available in your account settings dashboard.

How do you handle third-party integrations?

All third-party vendors who may access PHI (e.g., cloud storage, analytics) are vetted and operate under signed BAAs. We do not share PHI with advertising networks.