Encryption
TLS 1.2 or higher in transit on every external endpoint. Database, object storage and credential storage encrypted at rest with AWS-managed keys.
Security & Compliance
Kavera collects symptom, mood, sleep and cognitive data outside the visit and routes it back to you. That only works if the data is handled with the same rigor as the rest of the chart.
One field. 30 minutes. Live demo with a clinician.

HIPAA
Every practice executes a Business Associate Agreement before handling PHI. Access is minimum-necessary by role: a front-desk user assigning a battery does not see item-level responses; the reviewing clinician does. Patients are told what is collected and why before the first instrument.
Controls
TLS 1.2 or higher in transit on every external endpoint. Database, object storage and credential storage encrypted at rest with AWS-managed keys.
Email-delivered verification code on every clinical sign-in. Sessions expire after 30 minutes of inactivity.
Clinician, NP or PA, MA, practice administrator and Kavera Managed staff each operate under a role scoped to their tasks. Managed staff access is limited to monitoring and documentation.
Every authenticated action, including logins, record reads, signatures and configuration changes, is written to an append-only log as required by 45 CFR § 164.312(b). The same log is the time and activity record behind RTM documentation.
Every practice has its own subdomain and data scope. A session issued for one tenant cannot be replayed against another.
Patient data lives in production, separated from development and testing.
Shared responsibility
Kavera owns platform safeguards: encryption, access control, audit logging, infrastructure, the BAA. Your practice owns workforce training, workstation security and appropriate use inside your HIPAA program. Treat this page as an input to your security risk assessment, not a substitute for it.
FAQ
Is Kavera HIPAA compliant?
Yes. Signed BAA, encryption in transit and at rest, role-scoped access, audit logging.
How is patient data encrypted?
TLS 1.2 or higher in transit. AWS-managed keys at rest for database, object storage and credentials.
Does Kavera require MFA?
Yes. Email-delivered codes on every clinical sign-in. 30-minute inactivity timeout.
Does Kavera keep an audit log?
Yes. Append-only, every authenticated action, per 45 CFR § 164.312(b).
How is data isolated between practices?
Per-practice subdomain and data scope. Tenant sessions are not transferable.
For your compliance team
A 30-minute demo includes a security walkthrough.