Security & Compliance

Compliance.

IntakeBella is built for healthcare. Every layer of the platform — from infrastructure to AI processing — is designed to protect patient data and satisfy compliance requirements.

HIPAA Compliant

IntakeBella is fully compliant with the Health Insurance Portability and Accountability Act. All protected health information (PHI) is handled in accordance with the HIPAA Privacy Rule, Security Rule, and Breach Notification Rule.

SOC 2 Type II

Our infrastructure and operations meet the Trust Services Criteria for security, availability, processing integrity, confidentiality, and privacy as defined by the AICPA.

AES-256 Encryption at Rest

All stored documents, extracted text, structured data, and patient information are encrypted using AES-256 encryption. Encryption keys are managed through a dedicated key management service with automatic rotation.

TLS 1.3 Encryption in Transit

Every connection to IntakeBella — API calls, dashboard sessions, webhook deliveries, and data transmissions — is secured with TLS 1.3. No data travels unencrypted.

Role-Based Access Control (RBAC)

Access to patient data and system functions is controlled through role-based permissions: Owner, Admin, Member, and Viewer. Each role has clearly defined capabilities, and access can be revoked instantly.

HIPAA Audit Logging

Every action in IntakeBella is logged: views, downloads, routing decisions, setting changes, login events, and API calls. Audit logs are immutable, timestamped, and retained for the full data retention period.

10-Year Data Retention

Documents are retained for 10 years after the last customer activity, meeting or exceeding HIPAA retention requirements. Data is only purged 10 years after explicit deletion or account inactivity.

99.9% Uptime SLA

Enterprise customers receive a 99.9% uptime service level agreement. Our infrastructure runs on redundant, geographically distributed systems with automatic failover.

24/7 Incident Response

Our incident response team monitors system health continuously. In the event of a security incident, our breach notification process activates immediately per HIPAA requirements.

PHI Auto-Detection

Every incoming intake is automatically scanned for protected health information. PHI is tagged, classified by HIPAA category (clinical, billing, administrative), and access-level restricted before any human views it.

Isolated Data Architecture

Each customer's data is logically isolated. No cross-tenant data access is possible. API keys, session tokens, and webhook secrets are unique per organization.

Business Associate Agreement

IntakeBella provides a signed BAA to every customer. Our BAA covers all data processing, storage, and transmission activities performed by the platform.

Ready to sign your BAA?

Every IntakeBella customer receives a Business Associate Agreement. Review and sign electronically.

Review & Sign BAA

Questions about our compliance program? Contact us at support@intakebella.com