HIPAA Readiness and Shared Responsibility
Last updated: July 11, 2026
Sapyyn is designed to support privacy-conscious healthcare referral workflows. HIPAA compliance is an organizational outcome, not a product badge, and depends on contracts, configuration, operating procedures, workforce practices, and the technical controls below.
Identity and Access
Authenticated users are authorized with stable user, provider, practice, and patient identifiers. Referral, note, document, billing, integration, and API access is tenant- and role-scoped.
Auditability
Referral creation, lifecycle changes, task activity, document access, administrative changes, and other sensitive operations generate audit records for operational review.
External Communications
Email and SMS bodies are limited to a neutral sign-in prompt. External messaging is disabled by default and requires explicit deployment approval. Full automation payloads require both a practice-bound endpoint and a separate environment gate.
Hosting and Storage
Production requires HTTPS, secure cookies, managed Postgres, protected document storage, monitored backups, tested restoration, secret management, and approved hosting arrangements. Storage safeguards depend on the deployed environment.
Before using Sapyyn for PHI
- Execute all required agreements, including a BAA where applicable.
- Approve every subprocessor and communication provider that may handle regulated data.
- Verify access, retention, backup, incident-response, and workforce policies.
- Keep optional analytics off on authenticated pages and keep external messages PHI-minimized.
- Complete a documented risk assessment and periodic access review.
Questions and agreements
Contact your Sapyyn account representative through the Contact page to confirm the current contracting, hosting, and subprocessor position before enabling PHI workflows.