HIPAA Compliant
SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA: platform controls plus the HIPAA/BAA add-on path, with PHI only after BAA execution and tenant activation.
Security & trust
What is SignalEDI?
What reviewers ask about
SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA: platform controls plus the HIPAA/BAA add-on path, with PHI only after BAA execution and tenant activation.
Role-based access and reviewable logs for regulated teams validating operational controls.
Public status and clear trust narrative instead of invented uptime or volume claims.
Customer workspaces stay scoped so partner data and account actions remain isolated during review.
Independent examination · HIPAA posture
SignalEDI completed an independent SOC 2 Type I examination (Johanson Group LLP). Report date: June 19, 2026. A Type I report describes controls at a point in time; it is not a Type II report over a period.
Report date: June 19, 2026
SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA. Platform controls plus the HIPAA/BAA add-on path; PHI only after BAA execution and tenant activation.
Customers can request the full report under NDA on request. Request in your account → Trust Center →
Healthcare service scope · evidence reviewed 2026-08-05
This matrix describes the enforced product boundary for operating HIPAA-compliantly under an executed BAA. It is not a third-party examination report; suspected Part 2 content stays prohibited on external AI and analytics paths.
| Service path | HIPAA | 42 CFR Part 2 | Enforced condition |
|---|---|---|---|
| SignalEDI core EDI processing | CONDITIONAL | CONDITIONAL | HIPAA requires an executed BAA and tenant activation. Part 2 additionally requires counsel-approved agreement evidence, privileged approval, policy acknowledgement, partner classification, and consent provenance. |
| Inngest workflow orchestration | METADATA_ONLY | METADATA_ONLY | Events may contain opaque job, gateway, tenant, and correlation references only; EDI and clinical payloads must remain server-side. |
| OpenAI | PROHIBITED | PROHIBITED | No PHI or Part 2 payload authorization is represented. Inputs use minimization and pattern-based redaction; suspected Part 2 content is denied before transmission. |
| Anthropic | PROHIBITED | PROHIBITED | No PHI or Part 2 payload authorization is represented. A corrective sub-processor notice is announced; suspected Part 2 content is denied before direct or failover transmission. |
| AWS Bedrock external model inference | PROHIBITED | PROHIBITED | No PHI or Part 2 model-inference authorization is represented; suspected Part 2 content is denied before invocation. |
| External OCR and document capture providers | PROHIBITED | PROHIBITED | Healthcare and suspected Part 2 documents remain blocked unless a separately reviewed, contracted, and technically authorized provider path is approved. |
| Marketing, analytics, outreach, and billing tools | PROHIBITED | PROHIBITED | Customer EDI payloads, PHI, and Part 2 records are outside these service paths. |
Enforce tenant, agreement, classification, consent, and provider gates fail-closed. Protect credentials and payloads with access controls, encryption, logging, and incident procedures. Maintain sub-processor disclosures, vendor assessments, and dated evidence for public claims.
Determine whether HIPAA or 42 CFR Part 2 applies and classify source programs and trading partners accurately. Obtain and retain valid patient consent or another lawful authorization where required. Configure users, roles, retention, destinations, and downstream recipients consistently with the executed agreements.
Public diligence paths
Use these links during procurement, healthcare diligence, and developer review.
SignalEDI supports HIPAA compliance for covered-entity and business-associate customers under an executed BAA: platform controls plus the HIPAA/BAA add-on path, with PHI only after BAA execution and tenant activation. A BAA is available on any paid plan via the HIPAA/BAA add-on; Enterprise includes the add-on. An executed BAA is required before transmitting PHI. See /pricing for the published add-on rate.
Start at the Trust Center for policy links, public status, and the current narrative on controls. Ask for an evidence inventory when your review needs implementation-specific detail; this page does not promise a certification or private report.
SignalEDI completed an independent SOC 2 Type I examination (Johanson Group LLP). Report date: June 19, 2026. A Type I report describes controls at a point in time; it is not a Type II report over a period. Customers can request the full report under NDA on request — sign in to your account and open Help → Open a ticket (choose Compliance). Prospects who are not yet customers can email sales@signaledi.com. There is no public download.
Critical account, integration, and operational actions are designed to leave reviewable evidence for operators and security reviewers. Confirm exact retention and export behavior for the applicable plan and workflow during diligence.
Review transport, storage, key-management, and subprocessor statements in the current public security documentation during procurement.
Start with public artifacts, then contact sales when your healthcare, API, or procurement team needs implementation-specific detail.
Explore SignalEDI
Pricing, checkout, solutions, support, partner requirements, and trust artifacts stay linked so buyers do not dead-end on a single page.
© 2026 SignalEDI Inc. All rights reserved.