HIPAA Compliance at COALA
Last Updated: October 2026
COALA is designed with HIPAA safeguards in mind. The platform includes a comprehensive set of technical, administrative, and physical safeguards to protect the confidentiality, integrity, and availability of protected health information (PHI). Below is a summary of the safeguards COALA includes.
Built-In Safeguards
COALA includes encryption, access controls, audit logging, and session management as foundational safeguards to support your HIPAA compliance obligations.
What COALA Includes
Encryption at Rest
All stored data — resident records, staff files, and documents — is encrypted at rest using industry-standard AES-256 encryption.
Encryption in Transit
Every request to and from COALA is secured with TLS/SSL encryption, protecting data as it travels between your device and our servers.
Multi-Factor Authentication
MFA is supported to add an extra layer of protection beyond passwords, reducing the risk of unauthorized account access.
Role-Based Permissions
Granular, role-based access control ensures each user only sees and edits what their role permits — administrators control all permissions.
Access Logging
Platform access events are logged, providing visibility into who accessed what and when.
Automatic Logoff / Session Expiration
Idle sessions automatically expire after a period of inactivity, reducing risk on shared or unattended devices.
Audit Trails
Comprehensive audit trails track key actions across the platform, supporting accountability and regulatory review.
Backups
Data is backed up regularly to support recovery and continuity in the event of an unexpected failure.
Restricted Database Access
Database access is tightly restricted to authorized services and personnel only — no open or public access.
Private S3 File Storage
Uploaded documents and files are stored in private, access-controlled object storage with signed URLs for secure, time-limited access.
Secure APIs
All platform APIs are authenticated, authorized, and encrypted — no unauthenticated or plaintext endpoints.
Least-Privilege Access
Services and personnel operate under least-privilege principles, meaning access is limited to the minimum required to perform a task.
Production / Dev Separation
Production and development environments are fully separated, preventing untested or unreviewed code from touching live user data.
At a Glance
Important Note on HIPAA Compliance
COALA provides the technical safeguards listed above to support your HIPAA compliance efforts. However, HIPAA compliance is a shared responsibility. As a covered entity or business associate, you remain responsible for your own policies, workforce training, Business Associate Agreements (BAAs), and overall compliance program.
This page describes platform safeguards and is not legal advice. For specific compliance questions, consult with a qualified HIPAA compliance professional.
Questions About Compliance?
If you have questions about COALA's safeguards or need documentation for your compliance review, please reach out: