Trust & security
Ask us for it
in writing.
Anyura handles protected health information for United States aesthetic clinics. This page states where it stands, including the parts that are not finished.
The data
HIPAA-eligible infrastructure
Records, documents and chart photos sit on AWS under a signed BAA, on HIPAA-eligible services only.
United States only, on purpose
Built for US clinics and stored in the US, so every rule it is designed around is one that applies to you.
Export is unconditional
Everything, at any time, in a format you can open, photos included — and no exit fee.
The people
Roles and permissions
Role-based permissions help teams manage who can see and do what, across a catalogue of individual keys rather than three fixed roles.
Every action has a name on it
Views, edits, exports and logins are recorded with the person, the record, the field that changed and where the request came from.
A trail that cannot quietly change
Entries are chained and integrity checked, so an alteration to the log is detectable rather than hidden.
What leaves
Vendors under the same terms
Email and text run through Twilio under a signed BAA, covering messaging and email in one agreement.
Outside the card data path
Stripe receives an amount, a currency and an id we mint — not a patient name and not a procedure name.
Reminders are not marketing
Transactional messaging is kept separate from marketing, and one opt-out suppresses both SMS and email together.
The one claim we will never make
There is no such thing as HIPAA certification.
No government body issues one, and any vendor using the phrase is either careless or counting on a buyer not knowing.
What exists is three things. Ask every vendor you are evaluating for them in writing, including us.
- Compliance with the Privacy, Security and Breach Notification Rules.
- A signed Business Associate Agreement.
- An audit trail that can be produced on request.
What the rules look like from inside
Permissions are a screen a clinic owner actually uses, and the trail is a screen a reviewer can be handed. Neither is a promise about a system you cannot see.
What is signed, and what is not
- Business Associate Agreement, with youSignedWith every clinic, before a single patient record is entered. Not on request, not at an enterprise tier, not after a negotiation.
- AWS Business Associate AgreementSignedEvery service in the architecture checked against AWS's own HIPAA-eligible list.
- Twilio HIPAA planSignedCovers the SMS and the email that leave the platform, under one agreement.
- SOC 2 Type IINot yetWe do not have a report. When we do, it will be on this page — and until then, ask us where it stands rather than taking a badge for an answer.
The boring part,
done properly.
Ask for the BAA, the audit trail and the export policy in writing. That is the whole evaluation.
Ask for the BAA