HIPAA Compliant SOC 2 Type II End-to-End Encrypted BAA Included

Your Patients' Data Is Sacred.
We Treat It That Way.

Sera was built from day one for healthcare. Every call, every transcript, every piece of patient data is protected by enterprise-grade security and full HIPAA compliance.

Our Commitment

Security Isn't a Feature. It's Our Foundation.

We built Sera specifically for healthcare practices that handle sensitive patient information every day. Security, privacy, and compliance are embedded in every layer of our platform — not bolted on as an afterthought.

0
Data Breaches — Ever
100%
Calls Encrypted End-to-End
BAA
Included with Every Plan

HIPAA Compliance

Full HIPAA Compliance, Not Partial.

Many AI tools claim to be "HIPAA-friendly." Sera is fully HIPAA compliant, covering every requirement across administrative, physical, and technical safeguards. We sign a Business Associate Agreement (BAA) with every client, and our infrastructure is audited annually.

What This Means for Your Practice:

  • Every call recording and transcript is treated as Protected Health Information (PHI)
  • Access to patient data is role-based and logged with complete audit trails
  • Data is encrypted in transit, at rest, and during processing
  • We conduct annual HIPAA risk assessments and remediation
  • Workforce training on PHI handling is mandatory for all Sera employees
  • Breach notification procedures follow HIPAA requirements

HIPAA Safeguard Framework

Administrative Safeguards
Security Officer & privacy team designated
Workforce training & security awareness programs
Annual risk analysis & management process
Incident response & breach notification plan
Physical Safeguards
SOC 2 certified data center facilities
Workstation & device management policies
Media disposal & re-use procedures
Technical Safeguards
Unique user identification & MFA
Automatic session timeout & access controls
Encryption of all ePHI (AES-256, TLS 1.3)
Complete audit logging & integrity controls

Encryption

Triple-Layer Encryption for Every Byte

Patient data is encrypted at every stage — from the moment a call connects to when your team reviews the summary.

Data in Transit

TLS 1.3

All data moving between callers, our servers, and your dashboard is encrypted with TLS 1.3 — the latest transport-layer security protocol. No exceptions, no fallbacks.

Data at Rest

AES-256

Call recordings, transcripts, and patient data stored in our databases are encrypted with AES-256, the same standard used by banks and government agencies.

Data in Processing

Isolated Ephemeral Compute

AI processing runs in isolated, ephemeral compute environments. Audio data is processed in memory, never written to disk, and the environment is destroyed after each call.

How It Works

Security at Every Step of the Call

From the moment a patient dials your number to when your team gets the summary, every step is secured and audited.

1

Call Received

Patient calls your practice number. Call routes through encrypted HIPAA-compliant telephony infrastructure.

TLS 1.3 + SRTP
2

AI Processing

Sera's AI processes the call in an isolated ephemeral environment. No data is persisted beyond what's needed.

Ephemeral Compute
3

Summary Generated

Structured call summary is created and encrypted with AES-256 before being stored in our secure database.

AES-256 Encrypted
4

Team Notified

Your team receives a notification through secure, authenticated channels. Dashboard access requires MFA.

MFA + RBAC

Infrastructure

Built on Enterprise-Grade Infrastructure

Our security posture is validated by independent auditors and built on industry-leading cloud infrastructure.

SOC 2 Type II Certified

Independently audited for security, availability, processing integrity, confidentiality, and privacy. Our SOC 2 Type II report is available upon request under NDA.

Annual Audit 5 Trust Principles Available Under NDA

End-to-End Encryption

Every piece of data is encrypted using TLS 1.3 in transit and AES-256 at rest. Encryption keys are managed through a dedicated key management service with automatic rotation.

TLS 1.3 AES-256 Auto Key Rotation

Cloud Infrastructure

Hosted on HIPAA-eligible cloud infrastructure with geographic redundancy, automated backups, and 99.99% uptime SLA. All data resides in US-based data centers.

US Data Centers 99.99% Uptime Auto Backups

Access Controls & Audit Logging

Role-based access control (RBAC) ensures team members only see what they need. Every access event, data query, and configuration change is logged with immutable audit trails.

RBAC MFA Required Immutable Logs

Data Privacy

What We Do — and What We Never Do — with Your Data

Transparency is non-negotiable. Here is exactly how we handle your patients' data.

We DO

Encrypt all patient data with AES-256 and TLS 1.3
Sign a BAA with every client before handling any PHI
Limit data access to authorized personnel only
Maintain complete audit logs of all data access
Delete your data upon request, with written confirmation
Conduct annual third-party security audits
Store all data exclusively in US-based data centers

We NEVER

Sell, share, or monetize patient data — period
Use your patient data to train our AI models
Store data outside of the United States
Access patient data without explicit authorization
Retain data beyond the agreed retention period
Share data with third parties without your consent
Use unencrypted channels for any PHI transmission

Documentation

Compliance Documentation

We maintain comprehensive documentation to support your compliance requirements. Available documents can be requested from our security team.

Document Description Availability
Business Associate Agreement (BAA) HIPAA-required agreement covering PHI handling, signed before any data processing begins. Included with Every Plan
SOC 2 Type II Report Independent auditor's report covering security, availability, and confidentiality trust service criteria. Available Under NDA
HIPAA Compliance Attestation Letter of attestation confirming Sera's compliance with HIPAA Privacy, Security, and Breach Notification Rules. Available on Request
Penetration Test Summary Executive summary of our most recent third-party penetration test results and remediation actions. Available Under NDA
Data Processing Agreement (DPA) Agreement outlining data processing terms, sub-processors, data transfers, and retention policies. Available on Request
Incident Response Plan Overview of our security incident detection, response, containment, and notification procedures. Available Under NDA
Subprocessor List Complete list of third-party subprocessors that may process data on behalf of Sera, with security details. Available on Request

FAQ

Security Questions, Answered

Common questions from healthcare practices evaluating Sera's security posture.

Is Sera fully HIPAA compliant?

Yes. Sera is fully HIPAA compliant across all three safeguard categories: administrative, physical, and technical. We sign a Business Associate Agreement (BAA) with every client, conduct annual risk assessments, maintain comprehensive policies and procedures, and undergo independent third-party audits. Our entire infrastructure, from telephony to data storage, is designed to meet or exceed HIPAA requirements.

Do you provide a BAA? Is it included in every plan?

Yes. A Business Associate Agreement is included with every Sera plan at no additional cost. We execute the BAA before any patient data is processed. We will never handle PHI without a signed BAA in place. You can request a copy of our standard BAA for legal review at any time.

Where is patient data stored?

All patient data is stored exclusively in US-based data centers on HIPAA-eligible cloud infrastructure. Data is encrypted at rest using AES-256 encryption. We maintain geographic redundancy for disaster recovery, but all replicas remain within the United States. We never transfer or store patient data outside of the US.

Is patient data used to train your AI models?

No. We never use patient data, call recordings, transcripts, or any PHI to train, fine-tune, or improve our AI models. Your patients' data is used solely to provide the service you have contracted for — answering calls, generating summaries, and delivering them to your team. This is a contractual commitment in our BAA and DPA.

What happens if there is a security incident?

We maintain a comprehensive incident response plan that follows HIPAA Breach Notification Rule requirements. In the event of a security incident, we will: (1) contain and investigate the incident immediately, (2) notify affected clients within 24 hours of discovery, (3) provide detailed breach reports per HIPAA requirements, (4) work with clients on any required regulatory notifications, and (5) conduct a post-incident review and implement corrective actions.

What access controls are in place?

Sera implements role-based access control (RBAC) at every level. Your team members only see the data relevant to their role. Multi-factor authentication (MFA) is required for all dashboard access. On the Sera side, access to production systems and patient data requires MFA, VPN, and explicit approval from our security team. All access events are logged in immutable audit trails.

Can I request deletion of all my practice's data?

Yes. You can request complete deletion of all your practice's data at any time. Upon receiving a written deletion request, we will permanently remove all PHI, call recordings, transcripts, and associated data within 30 days. We will provide written confirmation once the deletion is complete. Backup copies are purged within 90 days per our retention policy.

What is SOC 2 Type II and why does it matter?

SOC 2 Type II is an independent audit conducted by a certified third-party firm that evaluates our security controls over a sustained period (typically 6-12 months). Unlike Type I, which only evaluates the design of controls at a point in time, Type II verifies that our controls are operating effectively over time. Our SOC 2 Type II report covers all five trust service criteria: security, availability, processing integrity, confidentiality, and privacy.

Get in Touch

Talk to Our Security Team

Have questions about our security posture, need compliance documentation, or want a detailed security review? We are here to help.

Email Security Team

security@joinsera.us

Call Us Directly

(347) 653-1170

Book a Security Review

30-min deep dive

Your Staff Handles Patients.
Sera Handles the Phones.

Book a 15-minute demo and hear Sera handle real patient calls through your clinic's workflow.

Or try it now: (347) 653-1170