Built for PHI from the ground up.
Strata is HIPAA compliant, and we sign a BAA with every practice that handles PHI. Your imaging lives in a managed, secure cloud built for health data — encrypted in transit and at rest, with access audit-logged so you can see who opened what and when. Data stays in your chosen region.
HIPAA compliant
Strata is HIPAA compliant. Your imaging lives in a managed, secure cloud built for health data — not on a server in your closet.
We sign a BAA
A Business Associate Agreement is available to every practice that handles PHI.
You know where data lives
Data stays in your chosen region. Your studies aren’t scattered across an opaque network.
Encrypted in transit & at rest
Nothing sits in the clear — your studies stay encrypted on the managed store and in transit.
Audit logging
Access to studies is audit-logged so you can see who opened what, and when.
Who can open a study — and a record that they did.
You decide who reads, and every access is written down. When a record request or an audit lands on your desk, the answer is already in the log.
- Role-based access — admin, member, or viewer. Each organization gets its own isolated store; read-only users can look but never change.
- Write-only request links let an outside office send you studies without ever seeing your list — they expire, cap at 20 uploads, and can be revoked at any time.
- Every access and upload is audit-logged — who opened what, and when, ready for a compliance review.
- Access enforced on every request — permissions are checked server-side, not hidden in the UI, so a viewer can never reach what they shouldn’t.
Need it in writing for your compliance review?
We’ll send a security one-pager covering architecture, the BAA, data location, encryption, and audit logging — and answer your team’s questions directly.
Security questions before you commit?
Book a call — we’ll walk through the architecture, the BAA, and exactly where your data lives.