HIPAA Compliance & Data Security
Last updated: January 2026
Technical safeguards
Encryption in transit (TLS 1.3) and at rest (AES-256), strict role-based access controls, comprehensive audit logging, and automated session management.
Administrative safeguards
Documented security policies, mandatory workforce training on PHI handling, designated privacy & security officers, and routine vulnerability assessments.
Physical safeguards
Infrastructure hosted on SOC-2 and ISO-27001 certified data center facilities with biometric access barriers and redundant environmental protections.
Strict access boundaries
Patient record access is restricted strictly to the patient and verified care teams (doctors, pharmacists) directly assigned to active consultations or orders.
1. Our Security Commitment
Kycura is engineered around HIPAA Privacy, Security, and Breach Notification rules. While serving patients and providers across West Africa, we maintain international compliance architecture to safeguard sensitive Electronic Protected Health Information (ePHI).
2. Protected Health Information (PHI) Handling
Information stored on Kycura — including SOAP notes, prescriptions, laboratory reports, and video signaling session data — is protected using AES-256 encryption. Access privileges are checked on every API request.
3. Business Associate Agreements (BAAs)
Third-party integrations (e.g., Supabase PostgreSQL storage, Paystack checkout, Daily.co WebRTC signaling) execute strict data processing and privacy terms aligned with HIPAA standards.
4. Inquiries & Incident Reporting
For security disclosures or compliance inquiries, contact our Security Officer at privacy@kycura.com.