Security & Compliance
Administrative, technical, and physical safeguards Reinfora maintains to protect protected health information and support HIPAA compliance.
Last updated May 29, 2026
Overview
Reinfora is designed for organizations that handle PHI. Our security program aligns with HIPAA Security Rule requirements and industry best practices for healthcare SaaS. This overview summarizes key controls; detailed artifacts (policies, penetration test summaries, subprocessors) are available under NDA during security review.
Administrative safeguards
- Designated security and privacy leadership;
- Workforce screening and HIPAA training;
- Role-based access policies and least-privilege principles;
- Incident response and breach notification procedures;
- Business continuity and disaster recovery planning;
- Periodic risk assessments and control reviews.
Technical safeguards
- Encryption in transit (TLS 1.2+) for all application traffic;
- Encryption at rest for databases and object storage;
- Multi-factor authentication support for user accounts;
- Session management, automatic timeout, and secure authentication flows;
- Audit logging of authentication and sensitive administrative actions;
- Vulnerability management and secure development practices;
- Logical separation of customer organizations (tenant isolation).
Physical safeguards
Production infrastructure is hosted with cloud providers that maintain SOC 2 and ISO 27001 certified data centers with physical access controls, environmental monitoring, and redundant power and networking.
Subprocessors
We use vetted subprocessors for hosting, email, monitoring, and support tooling. Subprocessors with access to PHI are bound by agreements requiring HIPAA-aligned protections. Customers will be notified of material subprocessor changes according to contract terms.
Controls you manage
- User provisioning, deprovisioning, and role assignment;
- Device and endpoint security for workforce members;
- Policies for downloading, printing, or sharing PHI;
- Training on phishing, password hygiene, and incident reporting.
Security contact
Report vulnerabilities or incidents: celoeman@gmail.com
Request a security packet for vendor review: celoeman@gmail.com