Compliance

HIPAA & Compliance

Zentake is built as a HIPAA business associate. Security is the foundation of the platform, not an add-on — here is how we protect patient data.

Our role under HIPAA

When your practice uses Zentake to collect protected health information (PHI), Zentake acts as a business associate and your practice is the covered entity. Our responsibilities are defined by HIPAA and by the Business Associate Agreement (BAA) we sign with every customer.

Signed BAA on every plan

We provide a signed BAA to all customers at no additional cost, on every plan. The BAA governs how we may use and disclose PHI and commits us to the safeguards described below. Request a copy at support@zentake.com.

Safeguards

Technical

  • Encryption in transit (TLS 1.2+) and at rest (AES-256).
  • Role-based access controls and least-privilege access.
  • Multi-factor authentication for administrative access.
  • Audit logging of access to PHI.

Administrative & physical

  • Workforce training and confidentiality agreements.
  • Documented security policies and periodic risk assessments.
  • Infrastructure hosted in [hosting provider] facilities with physical controls.

Certifications & attestations

Zentake maintains [SOC 2 Type II] and aligns its controls to the HIPAA Security Rule. [List certifications and audit cadence; link report request process.]

Subprocessors

We use a limited set of vetted subprocessors (for example, hosting and payment processing) under contracts that require HIPAA-appropriate safeguards. A current list is available on request.

Breach notification

In the event of a breach of unsecured PHI, we will notify affected customers without unreasonable delay and within the timeframes required by HIPAA, and cooperate with your notification obligations. [Specify contact and process.]

Contact

For compliance questions, BAAs, or security documentation, contact support@zentake.com.