Skip to content

Security

HIPAA and SOC 2 at Terra: what we did and what it means for your practice

Terra is HIPAA compliant and SOC 2 compliant. A plain explanation of what each one is, what we put in place to get there, and what your practice still needs to do before the first real patient.

  • Terra team
  • 4 min read
On this page (4 sections)

Every clinician who looks at an AI scribe asks the same first question, and they are right to: is it HIPAA compliant? We can now answer yes, and add that Terra is SOC 2 compliant as well. This post explains what those words actually mean, what we did to earn them, and the parts that remain your practice's responsibility. We would rather you understand it than just see a badge.

Two different things

HIPAA and SOC 2 are often mentioned together, but they answer different questions.

HIPAA is a US law. Its Privacy and Security Rules say how protected health information (PHI) must be handled by covered entities, such as your practice, and by their business associates, such as Terra. There is no official HIPAA certification and no government body that issues one. A company that says it is "HIPAA certified" is describing a private course or assessment, not a legal status. Being HIPAA compliant means meeting the rules' requirements: safeguards, policies, training, agreements and breach procedures, and being able to show it.

SOC 2 is an audit framework from the American Institute of CPAs. An independent auditor examines a company's controls for security and related criteria and issues a report. The report describes the controls and, depending on its type, either their design at a point in time or how they operated over a period. It is not a law; it is evidence, written by someone who is not us.

What we put in place

Training and a reviewed program

Everyone on the Terra team has completed HIPAA training, and our HIPAA program was reviewed against the Privacy and Security Rules. That program covers risk assessment, access management, workforce policies, incident response and breach notification, contingency planning, and how we manage vendors that touch PHI.

Controls in the product

Most of what protects patient information is not a policy document. It is how the software behaves. Some of what is in Terra today:

  • Encryption in transit with TLS on every connection, and at rest for databases, file storage and backups.
  • Sessions with access tokens signed by Ed25519 that last 15 minutes, refresh tokens that rotate on every use, and automatic revocation if an old token is replayed. Cookies are HttpOnly, Secure and SameSite=Strict.
  • Passwords stored as bcrypt hashes of a SHA-256 pre-hash, never as text, and sign-in errors that never reveal whether an account exists.
  • Roles and patient access. Clinicians, assistants and administrators have different permissions, administrators cannot open charts at all, and a chart can be restricted to named people or care teams.
  • Audit history of workspace and identity actions, which managers can review and export as a verified snapshot.
  • Signed-note integrity. A signed note is frozen with a SHA-256 hash. Later changes are dated, attributed amendments.
  • Retention controls for raw audio, configurable after clinician review with a legal hold, and manual retirement of original document files.
  • Least data to AI providers. Drafts send only the sources shown to the clinician in the quote. The encounter header omits the patient's name, MRN and date of birth. Evidence research sends only de-identified searches the clinician approves.

An independent examination

For SOC 2, an independent auditor examined these controls and our supporting processes, and issued a report. We share the full report with customers and prospective customers under a non-disclosure agreement; the Compliance center lists its type, period and auditor.

Agreements all the way down

HIPAA requires a business associate agreement at each step that PHI travels. Terra signs a BAA with your practice, and our subprocessors that handle PHI, for hosting, database, AI models and speech recognition, are bound by business associate agreements with Terra. The subprocessor list shows each one, what it receives and where.

What it means for your practice

Terra being compliant does not make your use of it compliant on its own. HIPAA is shared work between a covered entity and its business associates. Here is the part that stays with you.

  1. Sign the BAA before real patients. It is free on every paid plan. Email security@useterra.si and we send it for electronic signature. The free trial is for synthetic patients only, so you can try everything first.
  2. Give everyone their own account. Shared logins break the audit trail and the access model. Invite each clinician and assistant with the right role, and remove access the day someone leaves.
  3. Get consent to record. Terra asks the clinician to confirm consent before every live session. Your state's law and your policies decide what that consent must look like.
  4. Set your retention policy. Decide how long raw audio should be kept after review and configure it. Transcripts and signed notes stay part of the medical record.
  5. Review before you sign. A draft is a proposal. The note you sign is your clinical record and your responsibility.
  6. Include Terra in your risk assessment. We are happy to complete a security questionnaire and share the SOC 2 report.

What we will keep doing

Compliance is not a finish line. Controls drift, products change, and new subprocessors get proposed. We will keep the subprocessor list current and email customers before adding one that handles PHI, keep our team's training current, and continue to be examined independently.

We will also keep being specific. If a feature has a limit, the Help Center says so. If something is not yet validated, we do not claim it is. That is the same standard we hold our AI to: show the source, or say you do not have one.

If you have a security question, a questionnaire or a BAA to sign, write to security@useterra.si. If you find a vulnerability, our disclosure policy explains how to report it.

Leave on time tomorrow.

Start with a synthetic visit, then bring Terra into your clinic when it feels right.

7-day free trial · no card required · HIPAA compliant