Praktend is built for dental back-office operations. PHI flows through the platform on every credentialing, billing, and records task. This page describes exactly which controls are in force, which BAAs are signed, and what we do not claim.
There is no such thing as "HIPAA certification." No government body or accreditation agency issues HIPAA certifications. Any vendor claiming to be "HIPAA certified" is using a marketing phrase, not a regulatory one. We will not use that phrase.
What HIPAA actually requires of a business associate is: a signed BAA with each covered entity, reasonable technical and administrative safeguards for PHI, and a breach notification procedure. All three are in place for Praktend.
Praktend's infrastructure runs exclusively on GCP, which is a HIPAA-eligible platform with a signed BAA covering Firestore, Cloud Run, GCS, and related services. The GCP HIPAA BAA was accepted via the Google Cloud Console on 2026-06-04.
These controls map to the HIPAA Security Rule's technical safeguard requirements (45 CFR 164.312).
Per-company data isolation enforced at the Firestore security rules layer. Two-axis role model. Sessions use short-lived signed cookies, not long-lived tokens.
LiveStructured audit log on every agent action and approval. Append-only with idempotency key and reversal pointer on every write. Centralized Cloud Logging on every Cloud Run service.
LiveAES-256 at rest across Firestore, GCS, Cloud Run, and Secret Manager. Checksums on GCS objects. Decision graphs trace every claim back to a source record.
LiveGoogle Workspace login is required. Required MFA policy is in build. Google handles identity verification; Praktend adds app-layer role enforcement.
BuildingTLS 1.3 on every public endpoint via Firebase Hosting and Cloud Run. HSTS preloaded. No plain-HTTP fallback permitted.
LiveInherited from GCP. Google Cloud data centers hold ISO 27001, SOC 2, and HIPAA-eligible certifications. No Praktend-owned physical infrastructure exists.
LiveWorkforce security training and sanction policy are in build. Security incident response procedures and risk analysis documented and under review.
BuildingProduction LLM calls route through Vertex AI on GCP (covered by the GCP HIPAA BAA). Anthropic-direct API is prohibited in production. PHI is filtered at source before agent context assembly.
LiveA Business Associate Agreement is signed with every customer before any protected health information flows through Praktend. The BAA defines how Praktend may use PHI, requires breach notification, and sets retention and return/destruction obligations.
Sample BAA text is available on request. The signed BAA is executed electronically before onboarding. If you have a custom BAA template from your covered entity, send it and we will review and sign it.
No such thing exists. We will never use this phrase. If you see a vendor claiming "HIPAA certified," ask them who issued it and what the scope is. There is no federal certification program.
MFA is supported and encouraged on every operator account via Google Workspace. Policy-level enforcement that blocks login without MFA is in active build and is not yet live. If your procurement requires policy-enforced MFA today, note this gap.
Anthropic does not currently offer a HIPAA BAA for its direct API. This is why production PHI flows route through Vertex AI on GCP (which is covered). Anthropic-direct is prohibited for production PHI workloads in this platform.
Send your BAA, your questionnaire, or your specific requirement. Reply within twenty-four hours.
Send a question →