Back to Home
Clinical Security Standards

HIPAA Compliance & Data Security

Last updated: January 2026

Technical safeguards

Encryption in transit (TLS 1.3) and at rest (AES-256), strict role-based access controls, comprehensive audit logging, and automated session management.

Administrative safeguards

Documented security policies, mandatory workforce training on PHI handling, designated privacy & security officers, and routine vulnerability assessments.

Physical safeguards

Infrastructure hosted on SOC-2 and ISO-27001 certified data center facilities with biometric access barriers and redundant environmental protections.

Strict access boundaries

Patient record access is restricted strictly to the patient and verified care teams (doctors, pharmacists) directly assigned to active consultations or orders.

1. Our Security Commitment

Kycura is engineered around HIPAA Privacy, Security, and Breach Notification rules. While serving patients and providers across West Africa, we maintain international compliance architecture to safeguard sensitive Electronic Protected Health Information (ePHI).

2. Protected Health Information (PHI) Handling

Information stored on Kycura — including SOAP notes, prescriptions, laboratory reports, and video signaling session data — is protected using AES-256 encryption. Access privileges are checked on every API request.

3. Business Associate Agreements (BAAs)

Third-party integrations (e.g., Supabase PostgreSQL storage, Paystack checkout, Daily.co WebRTC signaling) execute strict data processing and privacy terms aligned with HIPAA standards.

4. Inquiries & Incident Reporting

For security disclosures or compliance inquiries, contact our Security Officer at privacy@kycura.com.