Compliance
Standards
Built for Healthcare. Designed for Trust.
Handling healthcare data means protecting the privacy and security of every patient record.
Our platform is built from the ground up to meet HIPAA requirements and has successfully completed a SOC 2 Type II audit, giving organizations confidence that their data is processed and stored with industry-leading safeguards.
HIPAA Compliance
The Health Insurance Portability and Accountability Act (HIPAA) sets the benchmark for protecting sensitive patient information in the United States.
We maintain full HIPAA compliance across every stage of our workflow Upload → Convert → Download so that clinical documents, FHIR outputs, and all intermediate data remain protected.
Key practices include:
- Business Associate Agreements (BAA): Available to all covered entities and partners.
- Access Controls & Monitoring: Strict role-based permissions, single sign-on (SSO), and continuous activity logging.
- Encryption Everywhere: All data encrypted in transit (TLS 1.2+) and at rest (AES-256).
This ensures that when you upload a messy healthcare document, the resulting structured FHIR output is handled in a way that satisfies HIPAA’s Privacy and Security Rules.
SOC 2 Type II Certification
We have completed our SOC 2 Type I and Type II process. Please checkout Curiflow Trust Center to request the SOC2 report.
Why This Matters
Compliance is more than a checkbox, it protects your organization and your data:
- Safeguards PHI (Protected Health Information) with proven technical and administrative controls.
- Supports seamless interoperability with FHIR-ready outputs while meeting regulatory requirements.
- Reduces risk for audits and third-party assessments, enabling faster onboarding and partnership approvals.
Whether you’re processing a handful of PDF charts or running high-volume batch conversions, you can trust that every job is backed by rigorous, independently verified security standards.
