Security & compliance

Security and compliance, handled for you

Protecting patient data is the baseline, not a feature. Here's how we handle it — in plain language.

Branzino Health security seal — HIPAA-aligned practices, signed BAA, encrypted in transit and at rest

Signed BAA with every practice  ·  Encrypted in transit & at rest  ·  Audit-logged

What's built in

HIPAA-compliant

Built to the HIPAA Security and Privacy Rules from day one, not retrofitted.

BAA with every practice

A Business Associate Agreement is available on request and signed before you ever see a patient in the system — at no extra cost.

Encrypted in transit & at rest

All data is protected with TLS in transit and strong encryption at rest.

Role-based access control

Every user sees only what their role allows. Admins control who can do what.

Audit logging

Access and changes are recorded, so you always know who touched a record.

Backups & monitored uptime

Automated backups and hosted, monitored infrastructure keep you running.

Verifiable foundations

Built on independently audited infrastructure

Branzino runs entirely on Google Cloud. The infrastructure layer under your data — servers, storage, networking — is covered by Google's own independent audits, which you can verify yourself rather than take our word for.

SOC 2 & ISO 27001

Google Cloud maintains SOC 1/2/3, ISO/IEC 27001, 27017 and 27018 certifications for the platform Branzino runs on. See Google Cloud's compliance offerings.

HIPAA-eligible services

We build only on Google Cloud services covered by Google's HIPAA implementation, and Google signs its own BAA for that infrastructure. See Google Cloud & HIPAA.

What's ours to prove

Those certifications cover the infrastructure — the application controls above it (access roles, audit logs, encryption settings) are ours, and we describe them plainly below rather than borrowing a badge for them.

Compliance

Where we stand — plainly

We'd rather tell you exactly what's true than hide behind a badge.

Is Branzino HIPAA-compliant?

Yes — meaning we operate to HIPAA's Security and Privacy Rules: encryption in transit and at rest, role-based access control, append-only audit logging, and a signed BAA with every practice. HIPAA has no official government certification, so we describe what we actually do rather than claim a certificate that doesn't exist.

Do you sign a BAA?

Always, and before you go live. A Business Associate Agreement is available on request — email security@branzinohealth.com — and signing one is a standard part of onboarding for every practice, at no extra cost.

Where is my data hosted?

On Google Cloud infrastructure in the United States, using only HIPAA-eligible services under Google's BAA. Google Cloud maintains its own SOC 2 and ISO 27001 certifications for that platform — verifiable on Google's compliance page. Each practice's data is logically isolated from every other practice's.

Is Branzino itself SOC 2 certified?

Not yet — and we won't claim it until it's real. A formal SOC 2 audit is on our roadmap as we grow. In the meantime, the controls a SOC 2 audit checks for — encryption, access control, audit logging, least privilege — are already in place, and the infrastructure we run on is independently audited today.

Who can see my patients' records?

Only the people in your practice you grant access to, scoped by their role. Branzino staff do not access practice data except when you explicitly ask us to for support, and that access is logged like everyone else's.

Can I export my data if I leave?

Yes. Your data is always yours and always exportable in portable formats. There's no lock-in and no ransom for your own records.

Do you have a privacy policy?

Yes — our Privacy Policy covers both this website and the Branzino service, including how protected health information is handled under a BAA.

Report a concern

Found something? Tell us.

If you believe you've found a security issue in Branzino, email security@branzinohealth.com. We read every report, we respond, and we won't take legal action against good-faith research.

Your data is always yours

Export your patients, notes and billing whenever you want, in portable formats. No lock-in, no hostage fees, no reason to fear switching — to us or away from us.

Listed on Capterra GetApp Software Advice G2