Security & compliance

HIPAA compliance

Have HIPAA requirements for your customer conversations? Start with a review of your use case, data and deployment with our team.

Before using Spur with protected health information (PHI), you need written confirmation of a supported configuration and the required signed agreements.

Availability & pricing

The HIPAA compliance add-on is priced at $499 USD per month, in addition to your base Spur plan. It is arranged through our team and is not activated by a free trial or a standard plan subscription.

Availability depends on whether we can support your proposed use case. Before any PHI is processed, our team must confirm the supported configuration, complete the required agreements and approve activation in writing.

The add-on is quoted in USD and billed monthly, including when your base plan is billed annually. Base-plan discounts do not apply to this add-on.

What the deployment review covers

Bring an overview of your intended workflow to the demo. Use sample or synthetic data when discussing your requirements.

Data and workflows
What information you need to process, where it enters Spur and which workflows will use it.
Channels, AI providers and integrations
Which services are involved and whether they can be included in the agreed scope. A connection to Spur does not automatically make a service suitable for PHI.
Access and data handling
Your requirements for access controls, retention, deletion and operational safeguards, and whether the proposed configuration can meet them.

Only channels and integrations explicitly included in the agreed configuration may be used for PHI. This page does not establish approval for WhatsApp, Instagram or any other channel.

Business Associate Agreement

A Business Associate Agreement (BAA) sets out the responsibilities of parties handling PHI. Discuss your BAA requirements with our team during the review. Any required BAA and other agreements must be signed before PHI is processed in Spur.

Subscribing to a plan or booking a demo does not create a BAA. Our Data Processing Agreement and Privacy Policy are available separately for your review.

Your responsibilities

A software add-on alone does not make your organization HIPAA compliant. Your organization remains responsible for its own risk assessment, policies, staff training and appropriate use of the platform.

  • Limit access to authorized team members and follow the agreed configuration.
  • Use only the data, channels and integrations approved for your deployment.
  • Review changes with our team before expanding how you use PHI in Spur.

Start with a conversation

Book a demo and tell us about your HIPAA requirements. We will review the use case, discuss availability and outline the next steps for your team.

Book a demo