Security & HIPAA
How PaiKnight protects patient and provider data.
Healthcare data safeguards
PaiKnight operates as a HIPAA Business Associate of its provider clients. We access Protected Health Information (PHI) only to perform administrative reimbursement-coordination services, under a signed Business Associate Agreement, with administrative, physical, and technical safeguards consistent with 45 C.F.R. Parts 160 and 164.
Encryption
- Application fields: selected PHI fields use application-layer AES-256-GCM encryption.
- Documents: patient documents are stored separately and accessed through time-limited signed URLs.
- Browser traffic: production web traffic uses TLS.
Access controls
- Role-based access limits case handlers to assigned work; designated administrators have broader oversight access.
- MFA is enforced for PaiKnight internal staff and available to Provider users. Optional PIN unlock and inactivity locking protect active sessions.
- The application records selected material actions and PHI-access events for operational review.
- Provider-side access to reviewed PHI workflows requires a recorded Provider BAA. Internal-staff access requires a current HIPAA training record.
Payment separation
- Payment-method data is processed by Stripe rather than stored as raw card data in PaiKnight.
- If a payer reimburses a case, it pays the Provider directly. PaiKnight does not hold or route those funds.
Request a BAA
The Provider agreement includes PaiKnight's Business Associate Agreement. See the Business Associate Agreement and Privacy Policy for details.