Surfacing was designed from day one around a single constraint: patient data must never leave the patient's device. This document explains precisely how that works, and what it means for HIPAA compliance.
Because Surfacing operates entirely on-device with no server-side component, the vast majority of HIPAA technical safeguard requirements are satisfied by design — not by policy.
We have no servers that receive or store patient data. The app is serverless by design.
The on-device database is encrypted using AES-256, the standard required by NIST and referenced in HIPAA technical safeguards.
The app functions fully offline. No network calls are made during normal logging, viewing, or filtering operations.
Exported files are AES-256 encrypted with a user-set password before leaving the device. No plaintext PHI is transmitted.
The app contains zero third-party analytics, crash reporting, or tracking SDKs that could inadvertently transmit PHI.
Exported HTML files contain no external script or resource references. They load entirely from local content — no network requests when opened.
The app requires biometric authentication or a user-set PIN before access, preventing unauthorized access if the device is lost.
The app locks after 2 minutes of inactivity and when backgrounded — preventing unauthorized access on an unlocked device.
We offer the ability to customize report delivery workflows for healthcare organizations — configuring export parameters, delivery formats, and integration pathways to meet your specific terminal and compliance requirements.
Customize Delivery to Healthcare Terminals — Contact UsCustomization options vary by organization type and clinical workflow. Contact us to discuss your specific requirements.
45 CFR § 164.312 establishes the Technical Safeguards required under the HIPAA Security Rule. Here is how Surfacing addresses each requirement.
Requirement: Implement technical policies that allow only authorized persons or software programs to access ePHI.
Requirement: Assign a unique name/number for identifying and tracking user identity.
Requirement: Implement electronic procedures that terminate an electronic session after a predetermined time of inactivity.
Requirement: Implement a mechanism to encrypt and decrypt ePHI.
Requirement: Implement hardware, software, or procedural mechanisms that record and examine activity in information systems that contain or use ePHI.
Requirement: Implement policies to protect ePHI from improper alteration or destruction.
Requirement: Implement technical security measures to guard against unauthorized access to ePHI transmitted over electronic communications networks.
A Business Associate Agreement is required when a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity. Surfacing's serverless architecture means we never receive, maintain, or transmit patient data — so the BAA obligation typically does not apply to our software.
We are happy to provide technical architecture documentation to your compliance team. Contact us.
Need a technical architecture summary for your BAA review, IRB submission, or organizational risk assessment? We'll respond within 48 hours.
Nothing in this document constitutes legal advice. For compliance determinations specific to your organization, consult a qualified HIPAA attorney or compliance officer.