HIPAA Compliance & Business Associate Agreements
Last updated: March 3, 2026
1. HIPAA Overview
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards to protect individuals' medical records and other individually identifiable health information (collectively, Protected Health Information or "PHI"). Krasyn EMR is designed and operated to comply with HIPAA's Privacy Rule, Security Rule, and Breach Notification Rule.
2. Business Associate Agreement (BAA)
Krasyn EMR operates as a Business Associate under HIPAA. Before any PHI is processed through our platform, covered entities must execute a Business Associate Agreement with Krasyn LLC
To request a BAA or discuss compliance requirements:
- Email: compliance@krasyn.com
- Subject line: "BAA Request — [Organization Name]"
We will provide our standard BAA for review within two business days. Custom BAA terms may be negotiated for enterprise customers.
3. Technical Safeguards
Krasyn EMR implements the following technical safeguards to protect PHI:
Access Controls
- Unique user identification: Every user has a unique account with individual credentials
- Role-based access control (RBAC): Four role levels (Administrator, Physician, Nurse, Administrative Staff) with granular scope-based permissions
- Automatic logoff: Sessions expire after 20 minutes of inactivity in production
- Emergency access: Administrator role provides emergency access with full audit trail
Audit Controls
- Comprehensive audit logging: All PHI access, modifications, and administrative actions are logged
- Immutable audit trail: Audit records cannot be modified or deleted
- Audit schema: Timestamp, user ID, organization ID, patient ID, action type, resource ID, and request metadata
Integrity Controls
- Tenant isolation: Multi-layer enforcement ensures organizations can only access their own data
- No hard deletes: Clinical data uses soft-delete patterns to preserve data integrity
- Input validation: All data inputs are validated and sanitized
Transmission Security
- Encryption in transit: All data transmitted over TLS 1.2 or higher
- HTTPS-only: HTTP Strict Transport Security (HSTS) enforced in production
- Secure cookies: Session cookies marked Secure, HttpOnly, and SameSite=Strict
4. Physical Safeguards
- Cloud infrastructure: The application is hosted on Microsoft Azure (SOC 2 Type II certified), and PHI is stored in Google Cloud Firestore (SOC 2 Type II certified). Both providers operate under executed Business Associate Agreements as subprocessors (see Section 6).
- Encryption at rest: All stored data encrypted using AES-256
- Backup and recovery: Daily automated backups with 30-day retention and quarterly restore drills
5. Administrative Safeguards
- Security officer: Designated security and privacy officer
- Workforce training: Security awareness training for all personnel
- Incident response: Documented breach notification procedures compliant with the HIPAA Breach Notification Rule
- Risk assessment: Regular security risk assessments and vulnerability scans
6. Subprocessor BAAs
Krasyn EMR maintains BAAs with the following infrastructure providers that may process PHI:
- Google Cloud Platform (Firestore): Data storage and authentication
- Microsoft Azure: Application hosting and AI services
7. Breach Notification
In the event of a breach of unsecured PHI, Krasyn LLC will notify affected covered entities without unreasonable delay and no later than thirty (30) calendar days after discovery of the breach, in accordance with 45 CFR 164.410 and the Business Associate Agreement (the BAA's 30-day contractual commitment governs).