Why Auroa is HIPAA & FERPA Exempt — by Design
The first question every operator asks is: "Are you HIPAA compliant?"The honest answer is better than yes. Auroa never touches protected health information or student education records — so HIPAA and FERPA don't apply to what we do. That's a deliberate architectural choice, and it's why our customers sleep at night.
What Auroa tracks — and what it doesn't
- • Staff names, roles, and shift assignments
- • Credential expiration dates (CPR, MSDE, FBI Live Scan, background checks)
- • Attestations that a screening happened — not the screening content
- • Facility-level operational logs (incidents, shift attestations)
- • SHA-256 hashes of uploaded credential files for integrity proof
- • Patient or resident medical records (PHI)
- • Student names, grades, IEPs, or attendance (FERPA records)
- • Diagnoses, medications, care plans, or clinical notes
- • Child developmental assessments or family PII
- • Any data element that would trigger a HIPAA BAA or FERPA disclosure
Why "exempt by design" is stronger than "compliant"
Smaller attack surface
A breach of Auroa exposes credential expiration dates, not diagnoses or IEPs. That materially reduces your regulatory exposure, your cyber-insurance premium, and your notification obligations.
No BAA required
HIPAA Business Associate Agreements exist to bind vendors that handle PHI. We don't, so there's nothing to bind. Procurement clears in days, not months.
No FERPA exposure for schools
Private Pre-K–12 academies and school-age childcare programs can adopt Auroa without triggering FERPA vendor-review workflows — we only touch teacher credentials, never student records.
You still get audit-grade proof
Every credential upload is SHA-256 hashed and timestamped. Every shift attestation is immutably ledgered. State licensors (MSDE-OCC, OHCQ, VDH, CDPH, CDSS) get exactly the roster proof they need — no PHI, no PII bleed.
"But my board is going to ask…"
Will Auroa ever pursue HIPAA certification?
Only if we expand into modules that store PHI — and we have no plans to. Staff-folder compliance is a full-time problem and we intend to own it end-to-end.
How do you keep PHI out?
Our data model has no fields for diagnoses, medications, or clinical notes. Uploaded files are stored as opaque blobs with SHA-256 fingerprints; we never parse or index their contents. Our /auditor-vault view scrubs PII before it's shown to state inspectors.
What about state privacy laws (CCPA, VCDPA, MD Online Data Privacy Act)?
Standard consumer-privacy statutes still apply to the staff PII we do hold (names, emails, expiration dates). Auroa honors deletion and access requests within statutory windows. See our Privacy Policy for the full workflow.
Do you sign a DPA?
Yes. A Data Processing Addendum covering the staff PII we handle is available on request and is standard in our Enterprise contract.
Compliance without the compliance overhead.
See how staff-folder tracking clears audits faster than the PHI-heavy platforms you've been quoted.
Get My Quote