Security

Your residents’ records, locked down.

“Is our data safe?” is the first question most directors ask us. Here is exactly how Kordera protects it, in plain English. If your IT person wants the technical details, they are further down the page.

Encryption

Encrypted everywhere

Records are scrambled while they travel and while they sit on the server. The most sensitive details get a second lock on top.

  • Every connection is encrypted (HTTPS only)
  • The server's disk is encrypted
  • SSNs, Medicaid and insurance numbers, court case numbers, and signatures encrypted again on their own
  • Uploaded documents stored encrypted
Access

Only the right people see it

Each staff member sees what their role needs, and nothing more. Sensitive numbers stay hidden even from people who can open the chart.

  • Permissions set by role, adjusted to your agency
  • SSNs and ID numbers show only the last four digits
  • Seeing the full number means re-entering your password, and it is logged
  • Turn off an account and access ends immediately
Audit log

Every look is recorded

Every time someone opens or changes a record, Kordera writes down who, what, and when. Nobody can quietly edit that history - not your staff, and not us.

  • Every view and every change logged
  • The database itself refuses to edit or delete log entries
  • Checked for tampering every night
  • Ready when a surveyor asks “who has seen this record?”
Sign-in

Strong sign-in

Passwords alone are not enough for health records. Kordera adds a second step and blocks the weak spots attackers look for.

  • Two-step sign-in with an authenticator app or a passkey
  • You can require it for everyone, or for admins and billing
  • Passwords of 12+ characters, checked against lists of known leaked passwords
  • Repeated wrong guesses get blocked
Screens

Screens that lock themselves

A chart left open on a desk is a real risk. Kordera locks the screen after 20 minutes without activity and hides the record behind it.

  • Auto-lock after 20 idle minutes, across every open tab
  • Shared tablets lock faster
  • Unsaved work is kept until you sign back in
  • The lock hides records, not just the menu
Backups

Backed up every hour

If something goes wrong, your records come back. Backups are encrypted before they ever leave the server.

  • Hourly backups to a separate server
  • Encrypted before they leave
  • Kept for up to six months
  • Restores tested, not just assumed
Your own system

Your records are never mixed with anyone else’s.

Every agency gets its own installation and its own database. And we sign a Business Associate Agreement with you before go-live, so the HIPAA paperwork is handled from day one.

The details for your IT reviewer.

The same safeguards, in the terms they will ask about.

HIPAABuilt to Security Rule safeguards; Business Associate Agreement signed before go-live
TenancyDedicated installation and database per agency
In transitTLS on every connection, HSTS enforced, secure cookies
At restEncrypted disk volume for the database and stored files; AES-256 field-level encryption for SSN, Medicaid, insurance, court case numbers, and signatures; document storage encrypted
AuthenticationTOTP authenticator or WebAuthn passkeys; MFA enforceable for all users or privileged roles; 12+ character passwords screened against breach corpora; sign-in rate limiting
AuthorizationRole-based, capability-level permissions; masked identifiers with password re-entry to reveal, logged
Sessions20-minute idle lock across tabs (shorter on shared devices), records hidden behind the lock
Audit trailEvery PHI view and change logged; append-only enforced by database triggers; hash-verified nightly
LoggingSensitive fields scrubbed from application error logs
BackupsHourly, encrypted before leaving the server, stored off-server; retained up to six months; restore-tested
AI (KORA)Speech-to-text runs on the device, audio never leaves it; transcript text only to Google Vertex AI under a Google Cloud BAA; staff review every note

Security questions, answered straight.

Is Kordera HIPAA compliant?

Yes. Kordera is built to the HIPAA Security Rule's safeguards, every look at a record is logged, and we sign a Business Associate Agreement with your agency before go-live.

Is our data mixed with other agencies' data?

No. Every agency gets its own installation and its own database. Your residents' records are never stored alongside another agency's.

What happens if a staff laptop or tablet is stolen?

Records live on the server, not on the device, and the screen locks itself when it sits idle. Turn off that person's account and their access is gone immediately. Every record they opened is in the audit log.

Can we require two-step sign-in for everyone?

Yes. You can require it for all staff, or only for admins and the people who handle billing and sensitive fields. Staff can use an authenticator app or a passkey.

What does the AI see?

When KORA helps with a note, the audio stays on the staff member's device and is turned into text there. Only that text is sent to Google's AI service, which is covered by a Business Associate Agreement. Nothing is auto-signed - staff review every note.

Will you fill out our security questionnaire?

Yes. Send it over and we will answer it, and we are happy to get on a call with your IT person.

Bring your IT person’s questions.

Send us your security questionnaire, or bring your IT person to a demo. We will walk through all of it.

Not ready for a call? Send us what you pay today and we'll show you what you'd save →