Skip to main content
Kavera

Security & Compliance

Kavera collects symptom, mood, sleep and cognitive data outside the visit and routes it back to you. That only works if the data is handled with the same rigor as the rest of the chart.

Request demo

One field. 30 minutes. Live demo with a clinician.

Two female clinicians, one in a lab coat and one in navy scrubs, smile while working together at a laptop.

HIPAA

HIPAA compliant

Every practice executes a Business Associate Agreement before handling PHI. Access is minimum-necessary by role: a front-desk user assigning a battery does not see item-level responses; the reviewing clinician does. Patients are told what is collected and why before the first instrument.

Controls

Platform safeguards

Encryption

TLS 1.2 or higher in transit on every external endpoint. Database, object storage and credential storage encrypted at rest with AWS-managed keys.

Multi-factor authentication

Email-delivered verification code on every clinical sign-in. Sessions expire after 30 minutes of inactivity.

Role-based access

Clinician, NP or PA, MA, practice administrator and Kavera Managed staff each operate under a role scoped to their tasks. Managed staff access is limited to monitoring and documentation.

Audit log

Every authenticated action, including logins, record reads, signatures and configuration changes, is written to an append-only log as required by 45 CFR § 164.312(b). The same log is the time and activity record behind RTM documentation.

Tenant isolation

Every practice has its own subdomain and data scope. A session issued for one tenant cannot be replayed against another.

Environment separation

Patient data lives in production, separated from development and testing.

Shared responsibility

What each party owns

Kavera owns platform safeguards: encryption, access control, audit logging, infrastructure, the BAA. Your practice owns workforce training, workstation security and appropriate use inside your HIPAA program. Treat this page as an input to your security risk assessment, not a substitute for it.

FAQ

Common questions

Is Kavera HIPAA compliant?

Yes. Signed BAA, encryption in transit and at rest, role-scoped access, audit logging.

How is patient data encrypted?

TLS 1.2 or higher in transit. AWS-managed keys at rest for database, object storage and credentials.

Does Kavera require MFA?

Yes. Email-delivered codes on every clinical sign-in. 30-minute inactivity timeout.

Does Kavera keep an audit log?

Yes. Append-only, every authenticated action, per 45 CFR § 164.312(b).

How is data isolated between practices?

Per-practice subdomain and data scope. Tenant sessions are not transferable.

For your compliance team

Available under NDA

  • Business Associate Agreement template
  • Security Risk Assessment (45 CFR § 164.308(a)(1)(ii)(A))
  • Incident Response Plan
  • Disaster Recovery Runbook
  • Workforce Training Program

See it on your patients

A 30-minute demo includes a security walkthrough.

Request demoRequest documentation →

One field. 30 minutes. Live demo with a clinician.