Compliance & Trust
ChiroReports is built so that identifiable patient information never has to reach our servers. This page states exactly which safeguards are in place, which come from the platforms we run on, and which we do not have. We would rather tell you plainly than post a badge we cannot back up.
Last reviewed August 31, 2026.
Compliance status
HIPAA Safe Harbor de-identification
In place
Reports are built from de-identified text. Patient names and dates of birth are held in your browser and merged into the document only at print or export time. There is no HIPAA certification for any software product, so we describe the architecture rather than claim a certificate.
Encryption in transit and at rest
In place
All traffic uses TLS. Stored account data and saved report drafts are encrypted at rest by our hosting provider.
Per-account data isolation
In place
Every database table enforces row-level access rules, so one office account cannot read another's records. Privileged operations verify the caller's role on the server.
Payment data never touches our servers
Provided by our platform vendors
Card details are entered directly with our PCI-compliant payment processor. We store only a customer reference, plan, and status.
SOC 2 audited infrastructure
Provided by our platform vendors
Our hosting, database, email, and AI gateway providers maintain their own SOC 2 programs. That covers the platforms we run on, not an audit of ChiroReports.
ChiroReports SOC 2 Type II report
Not in place
We have not completed our own SOC 2 audit and do not claim one. If your organization requires a vendor SOC 2 report, contact us and we will tell you exactly where we stand.
Signed Business Associate Agreement (BAA)
Not in place
Because identifiable patient information is not transmitted to us, we do not act as a business associate with access to your patient records, and we do not currently sign BAAs.
How the de-identified workflow works
- You upload an imaging report. The file is opened and read entirely in your browser - it is never uploaded to us.
- Names, dates of birth, record numbers, dates, phone numbers, and social security numbers are replaced with tokens such as
[PATIENT]and[DOB]. - Only the de-identified text is sent to our servers and to the AI gateway.
- The patient name and date of birth you type into the Identity panel are stored only in your browser, and merged into the finished document in your browser at preview, print, or export time.
- Saved report drafts in your dashboard keep the tokens, not the patient identity, and are deleted on the retention schedule you choose in Settings.
What we never do
- We do not sell or rent your data, and we do not share it for advertising.
- We do not use your reports or clinical text to train AI models.
- We do not store the original imaging file or image you upload.
- We do not store patient names, dates of birth, or medical record numbers on our servers.
- We do not require patient identifiers to generate any report.
Subprocessors
These are the categories of service providers that process data on our behalf. Each one receives only what it needs to do its job.
Application hosting and edge delivery
Serves the ChiroReports web application and its server functions.
Data involved: Request metadata, IP address, and de-identified report content in transit.
Managed database, authentication, and file storage
Stores your account, office settings, and saved de-identified report drafts.
Data involved: Account email, office and provider settings, credit balances, de-identified report drafts.
AI gateway and model providers
Translates clinical language into everyday language and drafts report text.
Data involved: De-identified clinical text only. Identifiers are replaced with tokens before the request leaves your browser.
Transactional email provider
Sends sign-in, billing, support, and patient handout emails.
Data involved: Recipient email address and message content. Patient handouts include a first name and email you enter at send time.
Payment processor
Processes subscriptions, report credits, and affiliate payouts.
Data involved: Billing email, payment method (held by the processor), subscription and invoice records.
Your responsibilities
Because patient identities live on your device, the security of that device is yours to manage: screen locks, full-disk encryption, and per-person logins for staff. Use the export and clear controls under Settings → Data & Privacy when you change or retire a computer. Nothing here is legal advice, and it does not replace your practice's own HIPAA policies or your state's records retention requirements.
Reporting a security issue
If you believe you have found a vulnerability, email support@chiroreports.app with the subject line "Security" rather than disclosing it publicly. We aim to acknowledge reports within 3 business days. Please do not test against real patient data.
Questions from your compliance team
If a hospital, insurer, or attorney asks for a security review, send them to this page and then contact us. We will answer their questionnaire with the same facts stated above.
See also Security & HIPAA, Privacy Policy, and Terms of Service.