Skip to main content
Compliance

Healthcare-grade by default.

Reinfora was built from day one to meet the bar healthcare actually requires, not bolted on afterwards.

HIPAA-aligned

Encryption at rest and in transit, BAA available, and access controls scoped by role and team.

Audit logs

Every read, edit, and export is logged so investigations and audits don't require detective work.

Funder-ready docs

Medical-necessity language, signature blocks, and CPT/HCPCS alignment baked into every artifact.

What's inside

Compliance, in detail.

  • BAA available on every paid plan
  • AES-256 at rest, TLS 1.2+ in transit
  • Granular role-based access
  • Full audit logging

Role-based access control

Granular roles for RBT, BCaBA, BCBA, ops, and admin, with team scoping so people only see what they should.

Two-factor authentication

Required by default for clinical and admin roles. SSO available on Enterprise plans.

Data residency

Hosted on healthcare-grade US infrastructure with documented backup, retention, and incident response policies.

Vendor diligence

Sub-processor list published; SOC 2 in progress; BAA available on signature.

Common questions

Will you sign a BAA?+

Yes. A BAA is included with every paid plan. Enterprise customers can review our standard agreement and propose redlines.

Where is data stored?+

On healthcare-grade US infrastructure with encryption at rest, automated backups, and documented retention policies. See the Security page for full details.