Security & HIPAA Compliance
Last updated: June 15, 2026
1. Our Commitment
rekupr handles sensitive medical billing information, and we take that responsibility seriously. Although rekupr is not a HIPAA Covered Entity, we voluntarily apply safeguards consistent with HIPAA standards because your documents may contain Protected Health Information (PHI). We maintain a Business Associate Agreement with Google Cloud Platform for all services that process your document content.
2. Data Encryption
- In Transit: All connections use TLS 1.3 encryption, with HTTPS enforced across the entire platform.
- File Storage: Documents are stored with AES-256 server-side encryption on Google Cloud Storage.
- Database Fields: Sensitive fields such as patient names, procedure codes, and identifiers are encrypted at the application level using AES-256.
- Sessions: Session data is encrypted to prevent tampering or interception.
3. Passwordless Authentication
We use passwordless authentication via secure email links, which is more secure than traditional passwords:
- No passwords to steal: Eliminates risks from weak or reused passwords.
- Single-use tokens: Each sign-in link expires shortly after it is sent and can only be used once.
- Inherits email security: Benefits from your email provider's security protections, including 2FA.
- Rate limited: Protects against brute-force attempts.
- Google Sign-In: Optionally sign in with Google OAuth 2.0. Google OAuth is a separate service used solely for authentication, and it does not receive any of your document or health data.
4. Session & Access Controls
- Automatic timeout: Sessions expire after a period of inactivity.
- Concurrent session limits: We limit the number of simultaneous active sessions per account.
- Document isolation: We enforce ownership checks on document access, so your documents are scoped to your account.
- Role-based access: Organization features use role-based permissions to control who can view and manage documents.
5. Document Processing
- Encrypted throughout processing: Your data remains encrypted as it moves through our analysis pipeline, including in background jobs.
- Log redaction: Sensitive health information is redacted from application logs.
6. Data Minimization & Retention
- Original files removed promptly: Once your document is analyzed, the original uploaded file is automatically deleted from our systems, typically within 3 days. Your analysis results are preserved; only the original file is removed to minimize data exposure.
- Analysis results retained up to 7 years: Your bill analysis, extracted data, and reports are retained so you can reference them over time.
- Audit logs retained 6 years: Access and security event logs are maintained for compliance and investigation purposes.
- On-demand deletion: You can delete your account and associated data at any time from Account Settings.
7. Google Cloud Platform
All services that process your document content are consolidated under Google Cloud Platform, covered by a single HIPAA Business Associate Agreement (BAA):
- Document processing and analysis: OCR text extraction, AI-powered analysis, and error logging
- Encrypted storage: Temporary document storage with AES-256 encryption
Consolidating under one cloud provider with a single BAA simplifies our compliance posture and reduces the number of parties with access to your data.
Note: Google OAuth 2.0 (used for "Sign in with Google") is a separate service that only receives your email and name for authentication. It does not receive any document or health data and is not covered by the BAA.
8. Incident Response & Responsible Disclosure
In the event of a data breach affecting your information, we will notify affected users in accordance with applicable law. Notifications will include a description of the incident, the types of information involved, steps we are taking, and steps you can take to protect yourself.
If you discover a security vulnerability, please report it responsibly to paolo@rekupr.co. We appreciate the security research community's efforts in helping keep our users safe.
9. Questions or Concerns
If you have any questions about our security practices or want to report a security concern, please contact us:
Email: paolo@rekupr.co