Security at Kubo

Built to protect PHI.

Kubo protects PHI with HIPAA-aligned safeguards, a BAA with every practice, encryption in transit and at rest, and US-based hosting.

  • HIPAA-aligned
  • BAA with every practice
  • US hosting
  • Encrypted in transit & at rest

HIPAA by design

HIPAA safeguards,
built into the product.

Kubo is designed around the administrative, physical, and technical safeguards defined by the HIPAA Security Rule.

Administrative

Policies, training & access

Controls for who can access systems and how staff handle PHI.

  • Least-privilege access
  • Documented security policies
  • Workforce training
Physical

Where PHI is stored

PHI is hosted in US-based cloud infrastructure with managed physical security.

  • US-based cloud regions
  • Managed data centers
  • No PHI on local machines
Technical

Encryption & access controls

Software controls protect PHI and record access.

  • Encryption in transit & at rest
  • Role-based access
  • Audit logging

A BAA is signed with every practice before PHI is exchanged.

Infrastructure

Encrypted in transit
and at rest.

PHI is encrypted from capture through storage, and hosted in the USA.

In transit TLS 1.2+

Every connection between the app, our services, and your PMS is encrypted in transit.

At rest AES-256

Stored PHI is encrypted at rest with AES-256.

Location US hosting

Data is hosted with a major US cloud provider in US regions.

Access & audit

Role-based access,
with a full audit trail.

Each account gets only the access its role requires. Sign-in is protected with SSO and MFA, and every action on the record is logged.

Role-based access

  • Assistants Capture, draft & prepare the chart Draft
  • Clinicians Review, edit & sign the record Signs
  • Administrators Manage users, roles & locations Admin

Only a clinician can sign & finalize a record.

Sign-in & controls

  • Microsoft SSO Sign in with your Microsoft identity
  • Multi-factor authentication MFA available on every account
  • Audit logs User, action & time recorded
  • Least-privilege by default Access scoped to the role

Retention & ownership

Your data stays yours.

You control how long Kubo retains data and can request deletion at any time. Your PMS remains the system of record.

See how PHI and AI are handled

Questions & answers

The questions we hear most, answered plainly.

Is Kubo HIPAA compliant, and do you sign a BAA?

Yes. Kubo follows the administrative, physical, and technical safeguards of the HIPAA Security Rule, and we sign a Business Associate Agreement with every practice before any PHI is exchanged. DSOs can review and tailor BAA terms with their compliance team.

How is our data encrypted?

PHI is encrypted in transit with TLS 1.2 or higher and at rest with AES-256. This covers transcripts, notes, documents, and data synced to your PMS.

Where is our data hosted?

Kubo is hosted with a major US cloud provider in US-based regions, with data isolated per practice.

Who can access a patient’s record?

Access is role-based. Assistants capture and prepare drafts, clinicians review and sign, and administrators manage users and locations. Sign-in supports Microsoft SSO and multi-factor authentication, and every action is recorded in an audit log.

How long do you keep our data, and can we have it deleted?

Retention is configurable to match your practice and state requirements, and you can request deletion at any time. Once a note is signed and written back, your PMS is the system of record. Audio is discarded after transcription. See the Safety page for the full data lifecycle.

Do you offer enterprise agreements for multi-location groups?

Yes. DSOs and groups can sign a custom Enterprise License Agreement with tailored BAA terms covering every location, with centralized administration and per-location access controls.

Ready for your
security review.

Walk through Kubo’s safeguards with our team, or send us your security questionnaire and BAA.