Your patients' health data belongs in a vault, not a payment processor.
CopperTab is designed to keep PHI away from payment processors. A signed BAA comes with every plan, from day one.
Everything that makes a billing record medical.
Handled under the responsibilities defined in your executed BAA. AES-256 at rest, TLS in transit.
Only what's needed to process a charge.
No diagnosis, no plan details, no clinical context. Stripe sees a payment, not a patient record.
What covers you, and where we stand.
We'll never overstate where we are. Here's an honest look at our compliance posture today.
A signed BAA is included on every plan. It defines CopperTab’s responsibilities for handling PHI within the agreed services.
Designed from the ground up to keep PHI out of payment payloads, descriptors, and Stripe records. AES-256 at rest, TLS in transit, audit logs throughout.
Card data is securely stored on Stripe, so it never touches CopperTab servers. Stripe's certification covers card processing.
Frequently asked questions
Do you sign a BAA?
Yes. A signed BAA is included on every CopperTab plan. It defines CopperTab’s responsibilities for handling PHI within the agreed services.
Does the same approach apply to one-time payments?
Yes. CopperTab keeps PHI-bearing billing context in CopperTab for both one-time and recurring workflows. Stripe processes the payment using the information needed for that transaction. The executed BAA governs CopperTab’s handling of PHI within the agreed services.
What does Stripe actually see?
Only what's needed to process a charge: a card and an amount. No diagnosis, plan details, or clinical context ever reaches Stripe.
Where is PHI stored, and how is it protected?
Everything that makes a billing record medical stays in CopperTab. The executed BAA defines CopperTab’s responsibilities for handling that PHI within the agreed services. Data is encrypted with AES-256 at rest and TLS in transit, with audit logs throughout.
How is card data kept PCI compliant?
Card data is stored securely on Stripe and never touches CopperTab servers, so Stripe's PCI DSS certification covers card processing.
Bring us your hardest compliance questions.
We'll send the BAA, walk through the HIPAA architecture, and tell you where we stand on SOC 2. No pitch. No slides.
Book a 15-min call