Popnin

Popnin and HIPAA

For clinics, practices and anyone who would use Popnin with protected health information (PHI). Written to be checked against the rules, not to sell. Last reviewed October 2026.

The short answer

Popnin is built so that we cannot see or hear meetings, keep no recordings, and store very little. That satisfies most of what the HIPAA Security Rule asks of a video service's technology, and the table below says exactly how.

HIPAA compliance, though, is not a property a product can have on its own. It belongs to the health care provider's program and contracts. For a provider to use any video service with PHI, HIPAA requires a Business Associate Agreement (BAA) between the provider and the service, and the service must hold the same agreements with its own suppliers. Popnin does not offer a BAA yet: our hosting platform, Cloudflare, enters into them only on enterprise contracts that name the services in scope, and we have not put that chain in place. Until we have, do not use Popnin for PHI, however strong the encryption.

Why a BAA is needed even though we can't read anything

  • The U.S. Department of Health and Human Services (HHS) has said since 2016 that a cloud service holding encrypted PHI without the key is still a business associate. It calls this a "no-view" service and requires a BAA all the same.
  • The "conduit" exception that would make a BAA unnecessary is narrow: it covers services that only transmit data with transient access, like an internet provider or a courier. Popnin is more than that. We store meeting titles and invitee email addresses and names (encrypted at rest with a key we hold, so we could read them), up to ten minutes of chat ciphertext after a room empties, notes from abuse reports, and connection metadata such as IP addresses and times.
  • HHS's telehealth guidance is explicit: covered providers must use technology vendors that comply with the HIPAA Rules and will enter into business associate agreements. The pandemic-era enforcement discretion that allowed consumer video apps ended in 2023.

What Popnin does today, against the Security Rule

Safeguard (45 CFR 164.308–164.312)What Popnin does
Transmission securityHTTPS only with HSTS preload on every page and API call. Meeting audio, video, screen shares, chat and files cross Cloudflare's media servers and TURN relays as ciphertext, encrypted frame by frame in the browser (AES-256-GCM). Nothing travels between participants in the clear.
Encryption and decryptionMeeting content is end-to-end encrypted with a key derived in each participant's browser from the meeting code (PBKDF2, 600,000 rounds, then HKDF) or from the secret in an open link. The server never has the key. Stored personal data (host and invitee addresses and names, meeting titles, report notes) is encrypted at rest with an application key separate from the provider's disk encryption.
IntegrityEvery media frame and signalling message is authenticated encryption with replay protection; a tampered or replayed frame is dropped. Participants prove possession of the key before they are admitted, and anyone who has not is marked "unverified" in the encryption badge and receives only ciphertext.
Access control and authenticationHosts sign in with a one-time code emailed to them; there are no passwords to leak. Sessions last 30 days or until sign-out. Guests have no accounts: each joins with a personal link plus the meeting code or key, waits in a lobby by default, and can be removed, denied or locked out by the organizer. Guest links can be revoked.
Audit controlsDeliberately minimal: automatic request logging (which would capture cookies and links) is switched off; our own application logs keep no identifiers and are deleted after 7 days; the admin page sits behind Cloudflare Access with the token verified again by the server. There is no per-action audit trail of administrator access yet (see below).
Minimum necessary and retentionNo recordings on our side: recording is to the recorder's own device, and everyone in the meeting is told. Live captions and notes run on the device. Records about a meeting are deleted 30 days after it ends, chat ciphertext 10 minutes after the room empties; the full schedule is on the privacy page. No analytics, advertising or tracking.
Breach notification and legal demandsWe notify affected hosts and invitees before disclosing anything in response to a legal demand unless prohibited, and publish counts on the transparency page. A formal business-associate breach process (notice to the provider within the rule's 60 days) would be part of a BAA.
Physical safeguardsPopnin runs entirely in Cloudflare's data centers, covered by Cloudflare's own audited certifications (published in its trust hub); we operate no servers of our own.

What is missing before we could sign a BAA

  1. A BAA with Cloudflare that names every service we use: Workers, Durable Objects, D1, Realtime (SFU and TURN) and Email Service. Cloudflare offers BAAs to enterprise customers, with the covered services listed in the agreement.
  2. A BAA with the email provider that hosts our support mailbox, where bug and abuse reports arrive, or a rule that keeps PHI out of those paths.
  3. A written Security Rule program for Huff Data Systems as a business associate: risk analysis, policies, workforce training and sanctions, incident response, breach notification, and a yearly evaluation.
  4. Product changes: an audit log of administrator actions; a second sign-in factor for hosts (not required by the current rule, proposed in the January 2025 draft update, and expected by most providers); retention a customer can shorten; and an option to keep meeting titles out of invitation emails.
  5. Legal review, and a signed BAA with each provider before any PHI is involved.

When these are done, this page will say so, and the agreement will be available on request. We will not describe Popnin as "HIPAA compliant" before then.

If you are a provider and want to use Popnin now

  • Use it for conversations that involve no PHI: administration, training, supplier calls, anything without patient information.
  • If your compliance officer concludes that a particular use needs no BAA, still choose "require a code" so the meeting key never travels by email, keep meeting titles and invitee names neutral, keep any recording under your own policies, and don't paste patient information into chat, file names or bug reports.
  • Your own HIPAA obligations (policies, training, patient consent for telehealth) are unaffected by anything on this page.

Sources

  • HHS: Guidance on HIPAA and cloud computing (encrypted "no-view" services are business associates).
  • HHS: Can a cloud service provider be a conduit?
  • HHS: HIPAA rules for telehealth technology (vendors must sign BAAs).
  • Cloudflare: HIPAA FAQ (BAAs for enterprise customers; services in scope are named in the agreement).
  • Federal Register: proposed HIPAA Security Rule update (January 2025), still a proposal at the time of review.

Contact

Questions about this page, or interest in a BAA: .

Last updated October 2026. This page describes our position; it is not legal advice.

Sponsored byHuff Data Systems
Privacy·Terms·HIPAA·EFF privacy guidelines·Safety·Transparency
v26.10.09.0113