We use privacy-friendly, cookieless analytics (Plausible) plus one first-party cookie for anonymous visit counting — no advertising and no cross-site tracking. See our Cookie Policy and Privacy Policy.
Security & HIPAA
Every document uploaded to Sydra is protected health information under HIPAA. An operative note, an EOB, an insurance card — all of it. This page documents how it is handled, who can reach it, and what you can request in writing.
BAA available
For covered entities on request during contracting.
AWS Bedrock
Claude Sonnet 4 on HIPAA eligible infrastructure.
Encryption
AES 256 at rest, TLS 1.2+ in transit.
Tenant isolation
Strict per practice row level security.
SOC 2 aligned
SOC 2 aligned controls. Report available under NDA during evaluation.
Sydra is built to SOC 2 criteria for security, availability and confidentiality. We are aligned to those criteria and are not yet certified against them. The report is available under NDA, and we would rather say that plainly than let the badge imply otherwise.
Sydra runs on Claude via Amazon Bedrock. Claude is contractually barred from training on your PHI, and Bedrock is covered under our AWS Business Associate Agreement. Your claim data is processed inside the same HIPAA aligned boundary as the rest of your workflow.
AWS Bedrock is a HIPAA eligible service. AWS's HIPAA BAA covers Amazon Bedrock when used in the context of a covered healthcare workload. Sydra operates within that BAA scope.
When Sydra generates an IDR draft from your operative note, the operative note is processed by Claude via Amazon Bedrock. PHI in that document stays inside the AWS HIPAA eligible service boundary. No PHI is transmitted to Anthropic's systems or any other third party during generation, and no data is used to train the Claude model or any other model.
Within your practice: role based access control. You define which staff members can view, draft, approve, or export. Permissions are granted explicitly, not inherited by default.
Between practices: strict tenant isolation enforced at multiple layers — application logic, API authorization, database row level security, and audit logging.
Within Sydra: engineering access is governed by internal HIPAA training; the Full Service RCM team accesses PHI only for practices using Sydra + Support; leadership access is for quality review and escalated cases. No PHI is accessible to sales or marketing without an operational need.
Every log entry captures user name, email, user ID, timestamp (UTC to the second), action performed, record affected (submission ID, document ID), IP address, and session identifier. Logs are available to your account administrator on request.
Yes. Documents are stored in Amazon S3 with AES 256 server side encryption, with keys managed through AWS Key Management Service. All data between your browser and Sydra's servers is transmitted over TLS 1.2 or higher.
Sydra handles PHI under HIPAA controls, running on Claude via Amazon Bedrock, a HIPAA eligible AWS service, and operating within AWS's HIPAA Business Associate Agreement for that workload. Claude is contractually barred from training on your PHI, no PHI is transmitted to Anthropic's systems, and no data is used to train the Claude model or any other model. A standard BAA is available for all covered entities and business associates using Sydra to process PHI.
Within your practice, access is role based — you define which staff can view, draft, approve, or export. Between practices, strict tenant isolation is enforced at the application logic, API authorization, database row level security, and audit logging layers. Internally, engineering access is governed by HIPAA training, the Full Service RCM team only has access for practices using Sydra + Support, leadership has access for quality review, and no PHI is accessible to sales or marketing without an operational need.
Sydra production workloads run on AWS infrastructure in US regions.
Sydra maintains documented incident response procedures covering detection, escalation, containment, recovery, and customer notification. If an incident involves your PHI, notification follows the timeline specified in your BAA, which is 60 days per HIPAA.
Yes. Every log entry captures user name, email, user ID, UTC timestamp, action performed, record affected, IP address, and session identifier. Logs are available to your account administrator on request.