Xano TRUST CENTER
Xano
Loading…

Certifications

Attestation

HIPAA

Overview

HIPAA is the primary U.S. regulatory framework governing the protection of health information, including the HIPAA Security Rule, which requires administrative, physical, and technical safeguards for electronic protected health information; it is a legal and compliance framework rather than a universal standalone certification standard. For Xano as a SaaS platform and processor, HIPAA alignment means implementing controls and safeguards appropriate for supporting customers that handle protected health information, typically in the role of a service provider or business associate. For customers as controllers or covered entities, this helps demonstrate that the underlying platform is designed to support regulated healthcare use cases and the secure processing of ePHI, which can be an important part of their own HIPAA compliance obligations.

How Xano Aligns With Criteria

Xano maintains a range of contractual documents, policies, procedures, and operational controls to support its alignment and overall security posture. The examples below highlight key elements of our program in relation to HIPAA requirements, and do not represent a complete list:

  • Business Associate Agreement (BAA) - available after registration for the HIPAA add-on
  • Business Associate Subcontractor Agreement (BASA) - available after registration for the HIPAA add-on
  • Information Security Policy
  • Access Control Policy
  • Incident Response Procedure
  • Risk Management Policy
  • Internal Audit Program
  • InfoSec Management Review Meetings

Files

100%