How RafaNest protects patient records on AWS
June 26, 2026
RafaNest protects patient records with encryption, append-only clinical notes, an access log and a Business Associate Agreement with Amazon Web Services. "Secure" is easy to claim and hard to check, so this article explains each safeguard in plain terms, what it covers and what it leaves to you, so you can weigh it against your own HIPAA obligations.
What no software can promise
The U.S. Department of Health and Human Services (HHS) does not certify any software as HIPAA compliant, so treat a "certified" badge with suspicion. Compliance depends on the whole practice, including your policies, who has access and how you use the tools. Software can give you safeguards you can describe, and a vendor that will sign the right agreement. That is what follows.
Encryption at rest
There are two layers. The database that holds your records runs on Amazon Aurora with storage encryption turned on, so the underlying disks are encrypted. On top of that, RafaNest encrypts the most sensitive content itself before it is written. Clinical note text and the structured SOAP fields, insurance member IDs, tax IDs, care plan text and several other clinical details are encrypted with AES-256-GCM, using a key derived separately for each patient. In the database those values are unreadable without the key, which is kept out of the database.
Not every field is encrypted by the application. Data the system has to search or calculate on, such as appointment times and the billing codes attached to a visit, is protected by the database's storage encryption and access controls instead.
Append-only clinical notes
A saved clinical note cannot be edited or deleted. The database itself refuses updates and deletions on the notes table, so history cannot be quietly rewritten through the application. To correct a note you save a new version that points back to the one it replaces, and the earlier version stays on record. The one change the system allows on a saved note is whether the patient can see it in their portal.
Patients can also ask for a correction. They submit an amendment request from their portal and you accept or decline it from your own review queue, which follows the amendment right in the HIPAA Privacy Rule. Clinical notes are part of the Professional plan.
An access log you can review
RafaNest records actions such as opening clinical records, creating a note, viewing a patient's documents, medications or vitals, and downloading a file. Each entry names who did it, which patient it concerned, when, and from which IP address. It records who touched a record and when, while changes to notes are kept as separate versions. The log is append-only for the same reason the notes are, and each entry carries a cryptographic signature made with a key that never sits in the database, so an entry inserted by someone outside the application can be detected. You can review it in the Access log page of your clinic admin.
A second step at sign-in
Clinic admin asks for a second step. The first time you open it on a device you set up a passkey, which is the fingerprint or face unlock you already use, and that device is then trusted for 30 days. If a passkey does not work, you can verify with a code sent to your email.
A Business Associate Agreement with AWS
HHS says that a cloud provider which stores or processes electronic protected health information for you is a business associate, and you need a written agreement with it. RafaNest runs on Amazon Web Services, including its database, sign-in service, file storage and hosting, under a signed Business Associate Agreement, and RafaNest provides a Business Associate Agreement to practitioners. Telehealth video uses Amazon Chime SDK, which falls under the same AWS agreement. Read the agreement itself, as you would with any vendor.
One kind of communication does leave that boundary. A text message passes through the mobile carrier, which is not a business associate, so keep reminders short and leave clinical detail out of them.
What is left to you
- Decide who on your team gets access, and remove people who leave.
- Keep your own policies, training and risk assessment up to date.
- Look at the access log and the amendment queue, because they only help if someone does.
Choosing a vendor? See the HIPAA questions to ask before you choose practice software. For video visits, read HIPAA and telehealth, what therapists need in place. Coming from another system? Read how to switch from SimplePractice to RafaNest. This is general information and not legal advice.

