HIPAA Compliance
Last updated on February 16, 2026.
Sonoshare ("Sonoshare," "we," "us," or "our") is committed to protecting the privacy and security of health information entrusted to our platform. This page describes how we meet our obligations under the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations (collectively, "HIPAA").
Why HIPAA Matters for Ultrasound Studios
Elective ultrasound studios capture sonogram images and videos that, when linked to an identifiable individual, constitute Protected Health Information ("PHI") under HIPAA. Even though elective studios operate outside the traditional clinical setting, the intimate nature of prenatal imagery — and the personal data associated with it — demands the same standard of care.
Sonoshare acts as a Business Associate to the studios that use our platform. That means we are directly accountable under federal law for safeguarding the PHI we store, process, and transmit on their behalf.
What Data We Protect
Within the Sonoshare platform, PHI includes:
- Sonogram images and ultrasound video recordings
- Client names, email addresses, and phone numbers
- Session dates and studio identifiers linked to individual clients
- Any metadata that could identify a specific individual in connection with their prenatal care
Administrative Safeguards
We maintain policies and procedures designed to manage the selection, development, implementation, and maintenance of security measures:
- Designated security responsibility. A designated security officer oversees HIPAA compliance across the organization.
- Workforce training. All team members with access to PHI receive training on HIPAA requirements and our internal security policies.
- Business Associate Agreements. We put Business Associate Agreements in place with the subcontractors who handle PHI on our behalf, including our infrastructure provider (Cloudflare) and our email and SMS providers (Resend and Twilio).
- Risk assessments. We perform regular risk assessments to identify and address potential vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Technical Safeguards
Our platform is built on technical controls that protect ePHI at every layer:
- Encryption at rest. Media stored in Cloudflare R2 and application data stored in Cloudflare D1 are encrypted at rest by the platform.
- Encryption in transit. All data transmitted between clients, our API, and our cloud services is encrypted using TLS 1.2 or higher.
- Access controls. Role-based access controls ensure that Clients can only view their own media and Studios can only access their own clients' data. Authentication is enforced via phone OTP and email magic links.
- Email security. SPF, DKIM, and DMARC are configured for all email communications to prevent spoofing and phishing.
Physical Safeguards
Sonoshare runs on Cloudflare's global infrastructure. Cloudflare's data centers maintain rigorous physical security controls — including 24/7 monitoring, restricted access, environmental protections, and independent third-party audits (such as SOC 2 and ISO 27001) — so that the facilities storing and delivering PHI meet strong physical-security standards.
Cloud Infrastructure
Our platform is built on the following services:
- Cloudflare R2 for encrypted media storage
- Cloudflare D1 for application and session data
- Cloudflare Workers and CDN for secure application hosting and content delivery
- Cloudflare Durable Objects and Containers for isolated video transcoding
- Resend (email) and Twilio (SMS) for notifications
We select providers that support the safeguards required for handling PHI and configure them accordingly.
Breach Notification
In the event of a Breach of unsecured PHI, Sonoshare will:
- Notify the affected Covered Entity (Studio) without unreasonable delay and no later than 30 days after discovery of the Breach.
- Provide details including: identification of affected individuals, a description of the PHI involved, recommended steps for affected individuals, and a description of investigation and mitigation actions taken.
- Cooperate with the Covered Entity in meeting their obligations to notify affected individuals and the Department of Health and Human Services as required by HIPAA.
Related Policies
For additional detail on how we handle data and our contractual commitments, please review:
- Privacy Policy — how we collect, use, and protect personal information across the platform
- Terms of Service — the general terms governing use of the Sonoshare platform
Contact Us
If you have questions about our HIPAA compliance posture or need to report a security concern, please contact us at:
Sonoshare
Email: hipaa@sonoshare.baby