Home Industries Pricing About Book a Demo
Compliance

HIPAA Compliance

PalmRoute is designed to support HIPAA-compliant operations for healthcare providers. Here's exactly how we protect your patients' data and yours.

Last reviewed: May 1, 2025 hipaa@palmroute.com

Important Note for Healthcare Providers

PalmRoute can operate in a HIPAA-compliant manner for covered entities and business associates in healthcare. However, HIPAA compliance is only activated when you have an executed Business Associate Agreement (BAA) with PalmRoute. Using PalmRoute without a BAA to process Protected Health Information (PHI) is not compliant. To request a BAA, email hipaa@palmroute.com.

Built on a secure foundation

Our infrastructure and processes are designed to meet the rigorous standards required by healthcare providers operating under HIPAA.

SOC 2 Type II Infrastructure

Hosted on AWS, which maintains SOC 2 Type II, ISO 27001, and FedRAMP certifications.

AES-256 Encryption at Rest

All stored data including call recordings, transcripts, and PHI is encrypted using AES-256.

TLS 1.2+ in Transit

All data transmitted between your systems, callers, and PalmRoute is encrypted in transit.

Role-Based Access Controls

Access to PHI is restricted to authorized personnel only, with full audit logging of all access events.

Business Associate Agreement

We execute a HIPAA-compliant BAA with every healthcare provider client upon request.

Annual Security Audits

Independent third-party penetration testing and security audits performed annually.

Ready to automate your practice
the compliant way?

Request your BAA and book a demo. We'll walk you through exactly how PalmRoute works within HIPAA requirements for your practice type.