> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://uploadcare.com/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://uploadcare.com/docs/_mcp/server.

# Establish HIPAA compliant ePHI data flows

> Build HIPAA compliant apps, and securely send and receive sensitive business data and protected information (PHI, ePHI) with Uploadcare.

HIPAA is US legislation providing data privacy and security provisions for
safeguarding electronic protected health information (ePHI). On our Custom
plan, Uploadcare can be configured to support HIPAA compliant workflow.

Let's cover what you can manage with Uploadcare in terms of HIPAA:

* Data encryption: all data is encrypted in transit.
* Access controls: you can provide minimum necessary access by using [signed URLs](/docs/security/secure-delivery/).
* Request monitoring and auditing: we log all network requests (POST, GET, PUT,
  DELETE) along with system logs.
* Backup: all customer data is backed up, you can configure custom backup storage.
* Risk mitigation: when updating our infrastructure, we perform checks to assure
  ePHIs are not exposed to risks.

Please note the following:

* You must be using the Uploadcare [Custom plan](https://uploadcare.com/pricing/).
* You must execute a [Business Associate Agreement](https://uploadcare.com/about/hipaa/) to ensure the
  proper handling of ePHIs.
* You must authorize delivery of uploaded files with [signed URLs](/docs/security/secure-delivery/)
  for your HIPAA compliant Uploadcare accounts.
* You must use two-factor authentication for anybody who has access to your
  Uploadcare account.
* You can't use [video processing](/docs/transformations/video-encoding/) or
  [file conversion](/docs/transformations/file-conversion/) features with a HIPAA
  compliant Uploadcare project, since they are not covered by our BAA.
* You must [configure a backup](/docs/uploads/storage/#file-storing-behavior).

Now, let’s go on to the implementation steps.

## Get an Uploadcare account \[#uc-account]

You will need an Uploadcare account, navigate here to [sign up](https://app.uploadcare.com/accounts/signup/).
Use an SSO or MFA authentication when setting up your account.

You can start with the free plan to explore the platform and set up your data
flows without uploading ePHIs. To set up [secure delivery](#authenticated-urls),
you're required to be on one of the [paid plans](https://uploadcare.com/pricing/).

To get started with Uploadcare, look through [our docs](/docs/).

Note, Uploadcare projects are separate environments that hold files and
settings. You can configure Uploadcare to power up your web app areas that
requires extra security.

## Protect ePHI from unauthorized access \[#authenticated-urls]

[Signed URLs](/docs/security/secure-delivery/) is a go-to feature when handling ePHIs.

By default, every uploaded file is available on our CDN. Signed URLs,
once enabled, will require a token together with a URL to gain access to a file
in your Uploadcare projects. Signatures must be generated on your backend.

Setting up signed URLs also requires a [custom CNAME](/docs/delivery/cdn/#custom-cdn-cname).

## Control who and when uploads the files \[#signed-uploads]

This is optional.

To completely control who and when can upload data to your Uploadcare projects,
navigate to your [Dashboard](https://app.uploadcare.com/) and enable
[Signed uploads](/docs/security/secure-uploads/).
Once enabled, each upload request will have to be signed to be accepted by our system.

## Back up your project

You can have all your stored files to be copied to a custom S3 bucket
automatically. [Connect the backup storage](https://app.uploadcare.com/projects/-/uploading/configure/) once,
and the system will do backups on a timely basis.

## Sign the BAA \[#conclusion]

Your HIPAA compliance will take effect only upon signing a Business Associate Agreement with
Uploadcare. [Contact our sales team](https://uploadcare.com/schedule-demo/) to request one.