Cogrova logo

Legal

HIPAA stance

Cogrova on cogrova.com is a business operations workspace (finance, documents, team access). This page clarifies our position regarding the U.S. Health Insurance Portability and Accountability Act (HIPAA).

Draft / placeholder. {brand} is not offered as a HIPAA-compliant electronic health record or covered entity system. Do not store protected health information (PHI) unless you have a signed BAA and written confirmation from us.

Not a healthcare product by default

The product is designed for company dashboards, files, and collaboration — not for clinical documentation or medical claims processing as a covered entity or clearinghouse.

Protected health information (PHI)

Unless we have executed a Business Associate Agreement (BAA) with your organization and explicitly enabled a HIPAA configuration, you must not upload PHI or use the service to create, receive, maintain, or transmit PHI on our behalf.

If you need HIPAA

Contact us before onboarding if you require a BAA or healthcare-specific controls. We may decline use cases that require HIPAA if the current product scope does not support them.

Security generally

We still apply industry-standard security practices for SaaS (access control, encryption in transit, monitoring). Those practices are not a substitute for a HIPAA compliance program.