Claima

Security & Compliance

Last updated: June 8, 2026

Claima is built for healthcare providers across all specialties. Every architectural decision — from our database to our AI providers — is made with HIPAA compliance and the protection of Protected Health Information (PHI) as a first-order requirement.

Compliance Posture

HIPAA-Ready
Business Associate Agreements (BAA)
Data Processing Agreement (DPA)
TLS 1.2+ encryption in transit
AES-256 encryption at rest
SOC 2 Type IIIn progress
Microsoft AppSource CertifiedIn progress
HITRUST CSFPlanned 2027

HIPAA Compliance

Claima acts as a Business Associate under HIPAA for all covered entity customers. We execute a Business Associate Agreement (BAA) with every customer before any PHI is processed. Our BAA covers:

  • Permitted uses and disclosures of PHI
  • Safeguards to prevent unauthorized use or disclosure
  • Breach notification within 60 days of discovery
  • Return or destruction of PHI upon contract termination
  • Sub-processor obligations passed through to all vendors handling PHI
To request a BAA or review our standard BAA template, contact security@claima.io.

Data Encryption

In Transit
All data transmitted between clients and Claima servers is encrypted using TLS 1.2 or higher. We enforce HTTPS across all endpoints with HSTS headers.
At Rest
All data at rest is encrypted using AES-256. This includes PHI stored in our PostgreSQL database (Azure Database for PostgreSQL, with encryption at the storage layer) and all backups.
API Keys & Secrets
All API keys, secrets, and credentials are stored as encrypted environment variables and never committed to source code or logs.

Access Controls

  • Role-based access control (RBAC) — users only access data belonging to their practice
  • JWT-based authentication with short-lived session tokens
  • Multi-factor authentication (MFA) support via Microsoft Azure AD SSO
  • All PHI access is scoped to authenticated, authorized sessions
  • Internal Claima staff access to production data requires explicit approval and is logged
  • Principle of least privilege applied to all service accounts and API integrations

AI & Third-Party Processors

Claima uses AI to power appeal letter drafting, billing insights, and claim assistance. PHI processed through AI systems is handled as follows:

  • AI subprocessor: AI-assisted features are provided by a third-party model provider. PHI is only shared with an AI subprocessor under a Business Associate Agreement, and is never used to train general-purpose models.
  • Claim.MD: EDI claim transmission is handled by Claim.MD under BAA as a HIPAA-compliant clearinghouse.
  • Stripe: Payment processing is PCI-DSS Level 1 compliant. Claima does not store full card numbers.
  • Microsoft Azure: PHI database hosted on Microsoft Azure, covered under Microsoft's HIPAA Business Associate Agreement.

A full list of sub-processors is available upon request.

Infrastructure & Availability

  • Hosted on Microsoft Azure App Service, with the PHI database on Azure Database for PostgreSQL Flexible Server
  • Automated daily database backups with 7-day retention and point-in-time restore
  • HTTPS enforced on all traffic; TLS 1.2 or higher in transit
  • Container-based deployments with health-checked restarts
  • United States data residency (Azure West US 3); no PHI is processed outside the United States

Audit Logging

  • All PHI access and modifications are logged with user, timestamp, and action
  • Authentication events (login, logout, failed attempts) are logged
  • Logs are retained for a minimum of 6 years in accordance with HIPAA requirements
  • Logs are immutable and stored separately from application data

Incident Response

Claima maintains a documented incident response plan. In the event of a PHI breach, we will notify affected covered entities within 60 days of discovery, in accordance with the HIPAA Breach Notification Rule. Notifications include the nature of the breach, PHI involved, steps taken to mitigate harm, and corrective actions implemented.

Certifications Roadmap

SOC 2 Type IIIn progress — audit period begins Q3 2026
HITRUST CSFPlanned Q1 2027
Microsoft AppSource CertificationIn progress — submission Q3 2026

Responsible Disclosure

If you discover a security vulnerability in Claima, please report it responsibly to security@claima.io. We will acknowledge receipt within 24 hours and work to resolve confirmed vulnerabilities promptly. We do not pursue legal action against researchers who report issues in good faith.

Contact

Claima, Inc. — Security Team

Security inquiries & BAA requests: security@claima.io

Privacy inquiries: privacy@claima.io

General support: support@claima.io