Compliance.
IntakeBella is built for healthcare. Every layer of the platform — from infrastructure to AI processing — is designed to protect patient data and satisfy compliance requirements.
HIPAA Compliant
IntakeBella is fully compliant with the Health Insurance Portability and Accountability Act. All protected health information (PHI) is handled in accordance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.
SOC 2 Type II
Our infrastructure and operations meet the Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy as defined by the AICPA.
AES-256 Encryption at Rest
All stored documents, extracted text, structured data, and patient information are encrypted using AES-256 encryption. Encryption keys are managed through a dedicated key management service with automatic rotation.
TLS 1.3 Encryption in Transit
Every connection to IntakeBella — API calls, dashboard sessions, webhook deliveries, and data transmissions — is secured with TLS 1.3. No data travels unencrypted.
Role-Based Access Control (RBAC)
Access to patient data and system functions is controlled through role-based permissions: Owner, Admin, Member, and Viewer. Each role has clearly defined capabilities, and access can be revoked instantly.
HIPAA Audit Logging
Every action in IntakeBella is logged: views, downloads, routing decisions, setting changes, login events, and API calls. Audit logs are immutable, timestamped, and retained for the full data retention period.
10-Year Data Retention
Documents are retained for 10 years after the last customer activity, meeting or exceeding HIPAA retention requirements. Data is only purged 10 years after explicit deletion or account inactivity.
99.9% Uptime SLA
Enterprise customers receive a 99.9% uptime service level agreement. Our infrastructure runs on redundant, geographically distributed systems with automatic failover.
24/7 Incident Response
Our incident response team monitors system health continuously. In the event of a security incident, our breach notification process activates immediately per HIPAA requirements.
PHI Auto-Detection
Every incoming intake is automatically scanned for protected health information. PHI is tagged, classified by HIPAA category (clinical, billing, administrative), and access-level restricted before any human views it.
Isolated Data Architecture
Each customer's data is logically isolated. No cross-tenant data access is possible. API keys, session tokens, and webhook secrets are unique per organization.
Business Associate Agreement
IntakeBella provides a signed BAA to every customer. Our BAA covers all data processing, storage, and transmission activities performed by the platform.
Ready to sign your BAA?
Every IntakeBella customer receives a Business Associate Agreement. Review and sign electronically.
Review & Sign BAAQuestions about our compliance program? Contact us at support@intakebella.com