Not HIPAA covered today · no BAA yet
HIPAA support is coming to renamed.to
Patient records need a signed Business Associate Agreement first. We are building towards that. Until then, keep protected health information out of renamed.to, and tell us you need it.
Read the security overview- TLS 1.3
- in transit
- AES-256
- at rest on file storage
- SOC 2
- infrastructure and AI providers
- No training
- AI providers never train on your files
Signed Business Associate Agreement
Between your organisation and upspawn software UG, with matching agreements with every provider that touches your files.
Isolated US deployment for PHI
Separate storage, database and processing, hosted in the United States, kept apart from the standard service.
No PHI in analytics or notifications
Generated filenames can contain patient names. They stay out of product analytics, chat notifications and support tooling.
Retention in years, audit logs kept
Retention you set, audit logs never deleted with a click, and one subscription per organisation.
Questions
Something else about handling patient records? Ask us directly.
- Can I use renamed.to for PHI today?
- No. Without a BAA, documents containing PHI must not be uploaded or connected through a cloud folder.
- When will the HIPAA plan be available?
- We do not publish a date. Everyone on the waitlist is emailed the moment a covered plan can be signed.
- How will it be priced?
- As a subscription per organisation. A BAA is a contract with your organisation, not a per-document charge.