// hipaa compliance

Built for covered entities.
HIPAA-ready from day one.

InstaRoom provides the technical infrastructure for independent practitioners and clinics to conduct telehealth sessions in a HIPAA-ready environment. Not bolted on. Built in.

📋
Business Associate Agreement available

Required by HIPAA for covered entities. We provide a countersigned BAA within 2 business days.

Read BAA →
// technical safeguards implemented
Encrypted Video

WebRTC with RS256 JWT authentication. Video is peer-to-peer — never stored.

Access Controls

httpOnly cookie sessions. bcrypt password hashing. Token rotation on OAuth.

Digital Consent

Captured, timestamped, and stored before video opens on every session.

Geo-Verification

Client jurisdiction verified against provider licensed states before every call.

No PHI in Payments

Stripe handles all payment data. No card numbers or PHI in our payment flow.

TLS 1.2+ in Transit

All data encrypted in transit. HTTPS for API. WSS for signaling.

// hipaa framework

Compliance questions or to request a BAA — hello@instaroom.link