// hipaa compliance
InstaRoom provides the technical infrastructure for independent practitioners and clinics to conduct telehealth sessions in a HIPAA-ready environment. Not bolted on. Built in.
Required by HIPAA for covered entities. We provide a countersigned BAA within 2 business days.
WebRTC with RS256 JWT authentication. Video is peer-to-peer — never stored.
httpOnly cookie sessions. bcrypt password hashing. Token rotation on OAuth.
Captured, timestamped, and stored before video opens on every session.
Client jurisdiction verified against provider licensed states before every call.
Stripe handles all payment data. No card numbers or PHI in our payment flow.
All data encrypted in transit. HTTPS for API. WSS for signaling.
// hipaa framework
Compliance questions or to request a BAA — hello@instaroom.link