HIPAA & Compliance
Is VeriflowAPI HIPAA compliant?
VeriflowAPI is designed with healthcare compliance requirements in mind. We can sign a Business Associate Agreement (BAA) with customers on our Scale and Enterprise plans. Important: VeriflowAPI verifies license status from public government databases. We do not store or process Protected Health Information (PHI). The data we handle — names, NPIs, license numbers, and status — is publicly available information, not PHI. That said, if your platform uses VeriflowAPI as part of a broader healthcare workflow, a BAA may still be required by your compliance team. We accommodate this.Business Associate Agreement (BAA)
A BAA is available for Scale and Enterprise plan customers. To request a BAA, email support@veriflowapi.com with the subject line “BAA Request.” We will respond within 2 business days.Data we store
| Data type | What we store | Retention |
|---|---|---|
| Verification requests | Input parameters (name, NPI, state) | 7 years |
| Verification results | Full response including sources checked | 7 years |
| Certificates | Signed verification certificates | 7 years |
| Webhook events | Event payload and delivery status | 1 year |
| API keys | Hashed key only, never plaintext | Until deleted |
Data security
- All data in transit is encrypted using TLS 1.3
- Data at rest is encrypted using AES-256
- API keys are stored as one-way hashes — we cannot recover your key if lost
- Infrastructure is hosted on AWS with SOC 2 Type II certified data centers
- Access to production systems is restricted to essential personnel only