HIPAA & Compliance
Zentake is built as a HIPAA business associate. Security is the foundation of the platform, not an add-on — here is how we protect patient data.
Our role under HIPAA
When your practice uses Zentake to collect protected health information (PHI), Zentake acts as a business associate and your practice is the covered entity. Our responsibilities are defined by HIPAA and by the Business Associate Agreement (BAA) we sign with every customer.
Signed BAA on every plan
We provide a signed BAA to all customers at no additional cost, on every plan. The BAA governs how we may use and disclose PHI and commits us to the safeguards described below. Request a copy at support@zentake.com.
Safeguards
Technical
- Encryption in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access controls and least-privilege access.
- Multi-factor authentication for administrative access.
- Audit logging of access to PHI.
Administrative & physical
- Workforce training and confidentiality agreements.
- Documented security policies and periodic risk assessments.
- Infrastructure hosted in [hosting provider] facilities with physical controls.
Certifications & attestations
Zentake maintains [SOC 2 Type II] and aligns its controls to the HIPAA Security Rule. [List certifications and audit cadence; link report request process.]
Subprocessors
We use a limited set of vetted subprocessors (for example, hosting and payment processing) under contracts that require HIPAA-appropriate safeguards. A current list is available on request.
Breach notification
In the event of a breach of unsecured PHI, we will notify affected customers without unreasonable delay and within the timeframes required by HIPAA, and cooperate with your notification obligations. [Specify contact and process.]
Contact
For compliance questions, BAAs, or security documentation, contact support@zentake.com.