Compliance and Regulations

Built to satisfy the rules your clinic answers to

An aesthetic clinic sits under more regulation than most people running one signed up for. Protected health information, card payments, marketing texts, telehealth, record retention, and a different set of state rules depending on the address on your lease. This page states exactly where Anyura stands on each of them, including the places where the honest answer is not yet. If you are running a vendor review, start here, and hold us to every line of it.

HIPAA, and the agreement that makes it real

Anyura signs a Business Associate Agreement with every clinic before a single patient record is entered. Not on request, not at an enterprise tier, and not after a negotiation. The Security Rule is answered with specific controls rather than a paragraph of intent: patient data is encrypted in transit and at rest, access runs on role based permissions built around the minimum necessary standard, and every view, edit, export and login is recorded. The Privacy Rule obligations that fall on you as the covered entity are supported rather than replaced, because that responsibility is not something a vendor can take off your hands.

encrypted in transit and at rest

  • role based permissions built around the minimum necessary standard
  • every view, edit, export and login is recorded

a Business Associate Agreement

  • Not on request, not at an enterprise tier, and not after a negotiation

before a single patient record is entered

The one claim we will never make

There is no such thing as HIPAA certification. No government body issues one, and any vendor using the phrase is either careless or counting on a buyer not knowing. What exists is compliance with the Privacy, Security and Breach Notification Rules, a signed Business Associate Agreement, and an audit trail that can be produced on request. Ask every vendor you are evaluating for those three things in writing, including us.

There is no such thing as HIPAA certification. No government body issues one, and any vendor using the phrase is either careless or counting on a buyer not knowing.

Texting and email law, which is where clinics actually get caught

Marketing messages are governed by the TCPA and email by CAN-SPAM, and the fastest way to breach either is a system that treats a reminder and an advertisement as the same thing. Anyura keeps transactional messaging separate from marketing by design. Suppression lists and opt out reconciliation apply across SMS and email together, so a client who unsubscribes from one is unsubscribed from both. Clinics send from their own domain and their own provisioned phone numbers, which keeps consent attached to the business that actually obtained it.

Payments, and staying outside the card data path

Card data is handled by the payment processor and tokenised. Anyura is not a store of card numbers, which keeps the clinic's PCI DSS obligations to the narrowest scope available to a business that takes cards. Payments settle through Stripe Connect into the clinic's own connected account, so the clinic is the merchant of record and holds the direct relationship for disputes, refunds and payouts.

State law, because your address decides half of this

Beyond the federal floor, clinics answer to their own state. California adds the CMIA and CCPA and CPRA privacy rights, Texas adds HB 300, Washington adds the My Health My Data Act, and most states set their own medical record retention periods, good faith examination requirements and telehealth rules. Anyura is built for United States clinics only and stores patient data in the United States, which is a deliberate limit: every rule the product is designed around is a rule that actually applies to you.

Independent assurance, including what is not finished

A SOC 2 Type II audit is under way. It is not complete, this page will carry the report the day it is, and until then the line stays marked in progress rather than quietly implying otherwise. First party third party penetration testing is scheduled on the same terms, a public status page with incident history is being set up, and a versioned subprocessor list is in progress. Incidents affecting patient data are disclosed to affected clinics directly, not only on a status page.

  • A SOC 2 Type II audit is under way
  • penetration testing is scheduled
  • a public status page with incident history
  • a versioned subprocessor list

the line stays marked in progress rather than quietly implying otherwise

Your records, and the evidence that they were handled properly

The audit trail is chained and integrity checked, so alteration is detectable rather than hidden, and it exports to CSV and PDF for a defined period so a reviewer or an attorney can be given a window without being given access to your live system. Data export is unconditional: everything, at any time, in a format you can open, photos included, with no exit fee. Retention is set by you, on the schedule your state requires, rather than by a vendor default.

Questions

What clinics ask about Compliance and HIPAA

Q1
Is Anyura HIPAA certified?
Nobody is. HIPAA certification does not exist, because no government body issues one. What we offer is compliance with the Privacy, Security and Breach Notification Rules, a Business Associate Agreement signed with every clinic, and an audit trail we will produce on request.
Q2
Do you sign a BAA, and does it cost extra?
Yes, and no. A BAA is signed with every clinic before any patient record is entered, at no additional cost and without an enterprise tier attached to it.
Q3
Do you have SOC 2?
Not yet. The Type II audit is under way and the report will be published here when it completes. We would rather you learn that from us than during procurement.
Q4
Where is our patient data stored?
In the United States. Anyura is built for United States clinics only, so there is no scenario in which your records are replicated to a region under another regulator.
Q5
Can we get our data out if we leave?
Yes, at any time, including before you leave. A full export in a format you can open, photos included, with no exit fee.

Next step

Send us your security questionnaire. We answer them ourselves, in full, and we tell you when the answer is no.