HIPAA
Notice.
This HIPAA notice is a placeholder and will be updated prior to general availability. For questions about HIPAA compliance or BAA availability, please contact us.
Last updated: August 2026
Our Commitment to HIPAA Compliance
OpenShare is designed for use in healthcare environments where the protection of Protected Health Information (PHI) is required under the Health Insurance Portability and Accountability Act (HIPAA). We are committed to maintaining administrative, physical, and technical safeguards that meet or exceed the requirements of the HIPAA Security Rule. Specific compliance documentation will be provided prior to general availability.
Business Associate Agreements
For enterprise deployments, Business Associate Agreements (BAAs) are available. OpenShare's tunnels are end-to-end encrypted (WebRTC DTLS) and OpenShare stores no PHI; your data stays on your own infrastructure, where at-rest encryption remains your responsibility. To discuss a BAA or enterprise compliance requirements, please contact our team. BAA terms and execution procedures will be detailed here prior to general availability.
Data Handling Practices
Data transmitted through the OpenShare platform is end-to-end encrypted in transit (WebRTC DTLS). OpenShare does not store your integration engine data or PHI at rest; that data remains on your own infrastructure. Access to platform data is controlled through role-based access controls and audit logging. We maintain strict data segregation between organizations. Detailed data handling procedures and technical controls will be documented here prior to general availability.
Security Controls
Our platform implements security controls aligned with the HIPAA Security Rule, including access management, audit controls, integrity controls, and transmission security. We conduct regular risk assessments and maintain an incident response plan. Specific security control details and third-party audit results will be provided here prior to general availability.
Breach Notification
In the event of a breach of unsecured PHI, OpenShare will notify affected covered entities in accordance with the HIPAA Breach Notification Rule. Our breach notification procedures and timelines will be detailed here prior to general availability.
Contact Us
For questions about HIPAA compliance, BAA requests, or our security practices, please reach out through our contact page or email us at contact@openshare.health.