Security & compliance

Your patients' health data belongs in a vault, not a payment processor.

CopperTab is designed to keep PHI away from payment processors. A signed BAA comes with every plan, from day one.

Stays in CopperTab

Everything that makes a billing record medical.

Diagnosis, dose history, and clinical notes
Plan names, program details, visit history
Patient billing records and subscription logic
Invoice line items and receipt context

Covered under your BAA with CopperTab. AES-256 at rest, TLS in transit.

What Stripe sees

Only what's needed to process a charge.

amount$299.00
payment_methodtok_••••4242

No diagnosis, no plan details, no clinical context. Stripe sees a payment, not a patient record.

What covers you, and where we stand.

We'll never overstate where we are. Here's an honest look at our compliance posture today.

Business Associate Agreement (BAA)Available day one

Signed with every customer, on every plan. It defines exactly how we handle your patients' PHI, so that side of your compliance is locked in from day one.

HIPAA-aligned architectureBuilt in

Designed from the ground up to keep PHI out of payment payloads, descriptors, and Stripe records. AES-256 at rest, TLS in transit, audit logs throughout.

PCI DSS (via Stripe)Covered

Card data is securely stored on Stripe, so it never touches CopperTab servers. Stripe's certification covers card processing.

Frequently asked questions

Do you sign a BAA?

Yes. A signed Business Associate Agreement is included on every CopperTab plan from day one. It sets out how CopperTab safeguards the PHI you send us, so the vendor side of your HIPAA obligations is handled the moment you go live.

What does Stripe actually see?

Only what's needed to process a charge: a card and an amount. No diagnosis, plan details, or clinical context ever reaches Stripe.

Where is PHI stored, and how is it protected?

Everything that makes a billing record medical stays in CopperTab, covered under your BAA. Data is encrypted with AES-256 at rest and TLS in transit, with audit logs throughout.

How is card data kept PCI compliant?

Card data is stored securely on Stripe and never touches CopperTab servers, so Stripe's PCI DSS certification covers card processing.

Bring us your hardest compliance questions.

We'll send the BAA, walk through the HIPAA architecture, and tell you where we stand on SOC 2. No pitch. No slides.

Book a 15-min call