HIPAA Compliance

HIPAA Notice & Business Associate Agreement

STFE Systems operates as a HIPAA Business Associate. All Protected Health Information submitted to the platform is governed by a signed Business Associate Agreement.

BAA Required: A Business Associate Agreement must be signed before your facility submits any Protected Health Information (PHI) to the STFE platform. Contact compliance@stfe.io to initiate the BAA process.

STFE's Role Under HIPAA

STFE Systems Inc. is a Business Associate under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and its implementing regulations (45 CFR Parts 160 and 164). Your facility โ€” as the licensed healthcare provider โ€” is the Covered Entity.

As a Business Associate, STFE:

What PHI the Platform Processes

When your facility uses STFE for admission evaluations, the following types of PHI may be processed:

Shadow Audit: The bulk shadow audit feature is designed to operate on de-identified data. Facilities should remove all direct identifiers (name, DOB, MRN, SSN, Medicare ID) before submitting historical data for shadow audit. If PHI is inadvertently submitted, it is governed by the BAA.

Technical Safeguards

๐Ÿ” Encryption at Rest

All data encrypted with AES-256. Database-level encryption on AWS RDS.

๐Ÿ”’ Encryption in Transit

All communications over TLS 1.3. No unencrypted data transmission permitted.

๐Ÿ‘ค Access Controls

Role-based access (5 roles). Least-privilege principle. Multi-factor authentication for admin access.

๐Ÿ“‹ Audit Logging

Immutable SHA-256 hash-sealed audit records on every PHI access and clinical evaluation.

โ˜๏ธ HIPAA-Eligible Infrastructure

All data stored and processed on AWS HIPAA-eligible services (EC2, RDS, ElastiCache) in us-east-1.

๐Ÿ” Annual Security Review

Third-party penetration testing and a SOC 2 Type II audit are in progress. Results available under NDA.

Physical and Administrative Safeguards

Subcontractors (Downstream Business Associates)

STFE uses the following subcontractors who may have access to PHI. Each is bound by a Business Associate Agreement with STFE:

The following vendors do not have access to PHI:

Patient Rights (As Covered by the Covered Entity)

As a Business Associate, STFE supports Covered Entities in fulfilling patient rights under HIPAA:

Patients should contact their healthcare facility (the Covered Entity) directly to exercise these rights. STFE will cooperate with the Covered Entity's requests.

Request a Business Associate Agreement

A BAA is required before submitting any PHI. We typically turn around a signed BAA within 3โ€“5 business days.

Request BAA โ†’ compliance@stfe.io

Reporting a HIPAA Concern

If you believe STFE has violated your facility's HIPAA rights or any provision of our BAA:

STFE will not retaliate against any facility or individual for filing a good-faith HIPAA complaint.

Effective Date: May 1, 2026  |  Document Version: 1.0