Attestation
HIPAA is the primary U.S. regulatory framework governing the protection of health information, including the HIPAA Security Rule, which requires administrative, physical, and technical safeguards for electronic protected health information; it is a legal and compliance framework rather than a universal standalone certification standard. For Xano as a SaaS platform and processor, HIPAA alignment means implementing controls and safeguards appropriate for supporting customers that handle protected health information, typically in the role of a service provider or business associate. For customers as controllers or covered entities, this helps demonstrate that the underlying platform is designed to support regulated healthcare use cases and the secure processing of ePHI, which can be an important part of their own HIPAA compliance obligations.
Xano maintains a range of contractual documents, policies, procedures, and operational controls to support its alignment and overall security posture. The examples below highlight key elements of our program in relation to HIPAA requirements, and do not represent a complete list: