HIPAA Compliance

HIPAA Compliance at COALA

Last Updated: October 2026

COALA is designed with HIPAA safeguards in mind. The platform includes a comprehensive set of technical, administrative, and physical safeguards to protect the confidentiality, integrity, and availability of protected health information (PHI). Below is a summary of the safeguards COALA includes.

Built-In Safeguards

COALA includes encryption, access controls, audit logging, and session management as foundational safeguards to support your HIPAA compliance obligations.

What COALA Includes

Encryption at Rest

All stored data — resident records, staff files, and documents — is encrypted at rest using industry-standard AES-256 encryption.

Encryption in Transit

Every request to and from COALA is secured with TLS/SSL encryption, protecting data as it travels between your device and our servers.

Multi-Factor Authentication

MFA is supported to add an extra layer of protection beyond passwords, reducing the risk of unauthorized account access.

Role-Based Permissions

Granular, role-based access control ensures each user only sees and edits what their role permits — administrators control all permissions.

Access Logging

Platform access events are logged, providing visibility into who accessed what and when.

Automatic Logoff / Session Expiration

Idle sessions automatically expire after a period of inactivity, reducing risk on shared or unattended devices.

Audit Trails

Comprehensive audit trails track key actions across the platform, supporting accountability and regulatory review.

Backups

Data is backed up regularly to support recovery and continuity in the event of an unexpected failure.

Restricted Database Access

Database access is tightly restricted to authorized services and personnel only — no open or public access.

Private S3 File Storage

Uploaded documents and files are stored in private, access-controlled object storage with signed URLs for secure, time-limited access.

Secure APIs

All platform APIs are authenticated, authorized, and encrypted — no unauthenticated or plaintext endpoints.

Least-Privilege Access

Services and personnel operate under least-privilege principles, meaning access is limited to the minimum required to perform a task.

Production / Dev Separation

Production and development environments are fully separated, preventing untested or unreviewed code from touching live user data.

At a Glance

Encryption at Rest
Encryption in Transit
Multi-Factor Authentication
Role-Based Permissions
Access Logging
Automatic Logoff / Session Expiration
Audit Trails
Backups
Restricted Database Access
Private S3 File Storage
Secure APIs
Least-Privilege Access
Production / Dev Separation

Important Note on HIPAA Compliance

COALA provides the technical safeguards listed above to support your HIPAA compliance efforts. However, HIPAA compliance is a shared responsibility. As a covered entity or business associate, you remain responsible for your own policies, workforce training, Business Associate Agreements (BAAs), and overall compliance program.

This page describes platform safeguards and is not legal advice. For specific compliance questions, consult with a qualified HIPAA compliance professional.

Questions About Compliance?

If you have questions about COALA's safeguards or need documentation for your compliance review, please reach out:

COALACOALA

2880 Zanker Rd
San Jose, CA 95134

Contact

General / Company Inquiries

coalateam@gocoala.com

Technical Support

support@gocoala.com

Navigation

© 2026 Coala Technology Group, Inc. All rights reserved.