Security & Compliance
Last updated: June 8, 2026
Claima is built for healthcare providers across all specialties. Every architectural decision — from our database to our AI providers — is made with HIPAA compliance and the protection of Protected Health Information (PHI) as a first-order requirement.
Compliance Posture
HIPAA Compliance
Claima acts as a Business Associate under HIPAA for all covered entity customers. We execute a Business Associate Agreement (BAA) with every customer before any PHI is processed. Our BAA covers:
- Permitted uses and disclosures of PHI
- Safeguards to prevent unauthorized use or disclosure
- Breach notification within 60 days of discovery
- Return or destruction of PHI upon contract termination
- Sub-processor obligations passed through to all vendors handling PHI
Data Encryption
Access Controls
- Role-based access control (RBAC) — users only access data belonging to their practice
- JWT-based authentication with short-lived session tokens
- Multi-factor authentication (MFA) support via Microsoft Azure AD SSO
- All PHI access is scoped to authenticated, authorized sessions
- Internal Claima staff access to production data requires explicit approval and is logged
- Principle of least privilege applied to all service accounts and API integrations
AI & Third-Party Processors
Claima uses AI to power appeal letter drafting, billing insights, and claim assistance. PHI processed through AI systems is handled as follows:
- AI subprocessor: AI-assisted features are provided by a third-party model provider. PHI is only shared with an AI subprocessor under a Business Associate Agreement, and is never used to train general-purpose models.
- Claim.MD: EDI claim transmission is handled by Claim.MD under BAA as a HIPAA-compliant clearinghouse.
- Stripe: Payment processing is PCI-DSS Level 1 compliant. Claima does not store full card numbers.
- Microsoft Azure: PHI database hosted on Microsoft Azure, covered under Microsoft's HIPAA Business Associate Agreement.
A full list of sub-processors is available upon request.
Infrastructure & Availability
- Hosted on Microsoft Azure App Service, with the PHI database on Azure Database for PostgreSQL Flexible Server
- Automated daily database backups with 7-day retention and point-in-time restore
- HTTPS enforced on all traffic; TLS 1.2 or higher in transit
- Container-based deployments with health-checked restarts
- United States data residency (Azure West US 3); no PHI is processed outside the United States
Audit Logging
- All PHI access and modifications are logged with user, timestamp, and action
- Authentication events (login, logout, failed attempts) are logged
- Logs are retained for a minimum of 6 years in accordance with HIPAA requirements
- Logs are immutable and stored separately from application data
Incident Response
Claima maintains a documented incident response plan. In the event of a PHI breach, we will notify affected covered entities within 60 days of discovery, in accordance with the HIPAA Breach Notification Rule. Notifications include the nature of the breach, PHI involved, steps taken to mitigate harm, and corrective actions implemented.
Certifications Roadmap
Responsible Disclosure
If you discover a security vulnerability in Claima, please report it responsibly to security@claima.io. We will acknowledge receipt within 24 hours and work to resolve confirmed vulnerabilities promptly. We do not pursue legal action against researchers who report issues in good faith.
Contact
Claima, Inc. — Security Team
Security inquiries & BAA requests: security@claima.io
Privacy inquiries: privacy@claima.io
General support: support@claima.io