Compliance
Last updated: August 25, 2026
Kore. Studio builds websites, funnels, and automation systems exclusively for psychiatry and behavioral health practices. Because our work may involve systems that handle Protected Health Information (PHI) — including patient names, appointment details, and communications — we design our infrastructure and workflows with HIPAA requirements in mind.
Our goal is to help practices implement secure, responsible digital systems while recognizing that HIPAA compliance requires both appropriate technology and proper operational practices.
Our infrastructure and implementation services may cover systems we build and manage on your behalf, including intake workflows, automated communications, scheduling processes, and other digital systems where PHI may be involved.
This does not replace your practice's own HIPAA obligations, including:
HIPAA compliance is a shared responsibility between the technology systems implemented and the way your practice manages information day to day.
When connecting your systems with third-party platforms such as EHR systems, scheduling tools, payment platforms, or automation services, Kore. Studio evaluates the workflow requirements and available compliance considerations for each integration.
Before PHI is transmitted through connected systems, applicable agreements, security requirements, and platform capabilities should be reviewed to ensure the configuration aligns with your practice's compliance needs.
You own your practice's data at all times.
If services with Kore. Studio end, we will provide reasonable assistance with transferring or exporting available contacts, workflows, and associated project data as outlined in your service agreement and Terms of Service.
If you have questions about how a specific system handles PHI, or want documentation of our BAA coverage for your own compliance records, contact us at: