Skip to main content

We use cookies for essential site functions and anonymous analytics. Choose what to allow.

Accepts all cookies and closes this banner
Reject All
Back to Home
BAA Available

HIPAA & Healthcare Messaging

BAA available for Enterprise customers bridging healthcare collaboration platforms

BAA Available

Business Associate Agreement available for Enterprise customers

Encrypted

Encrypted in transit (TLS); OAuth tokens encrypted at rest

Transient

Message content not stored on the normal relay path

Require a BAA?

Enterprise customers processing Protected Health Information (PHI) can request our standard Business Associate Agreement.

Contact Sales

1. HIPAA and Messaging Bridges

HIPAA has no official certification: a vendor cannot be "HIPAA certified". What matters is whether the vendor will sign a Business Associate Agreement (BAA) and how it safeguards Protected Health Information (PHI) that passes through its service.

SyncRivo relays messages between Slack, Microsoft Teams, Google Chat, Webex and Zoom Team Chat. A BAA is available for Enterprise customers; healthcare organizations should sign one before routing PHI through SyncRivo.

2. Technical Safeguards

How SyncRivo protects data today:

• Encryption: data is encrypted in transit (TLS), and provider OAuth tokens are encrypted at rest.

• Access controls: owner, admin and member roles, with sign-in via Google or email + password and optional MFA (TOTP, passkeys).

• Logging: an activity log and security event history (JSON export).

• Webhook verification: inbound events from each chat platform are signature-verified.

3. Administrative Safeguards

What to review with any messaging vendor before routing PHI:

• BAA: SyncRivo's BAA is available for Enterprise customers.

• Sub-processors: a DPA and sub-processor list are available on request.

• Controls: ask for a security questionnaire and architecture review, which SyncRivo provides on request.

4. Hosting

SyncRivo is a cloud service; physical safeguards for the servers are provided by its hosting provider.

• Hosting: SyncRivo is hosted in the US on Google Cloud (us-central1).

5. Minimal Data Footprint

The safest PHI is PHI you don't store.

Message content is not stored on the normal relay path: SyncRivo keeps only message IDs so threads, edits and reactions stay in sync, and files pass through memory only. If you enable the optional retry queue, undelivered messages are held temporarily until they can be delivered.

This design reduces how much sensitive data sits in the bridge.

Three-Platform Bridges

Connect three enterprise messaging platforms simultaneously with SyncRivo's cross-platform bridges.

cookie_consent.banner.aria_announcement