Compliance
Last updated: August 02, 2026
Kore. Studio builds websites, funnels, and automation systems exclusively for psychiatry and therapy practices. Because our work regularly involves systems that touch Protected Health Information (PHI) — patient names, appointment details, and communications — we've built our infrastructure with HIPAA compliance as a foundational requirement, not an add-on.
Our infrastructure and BAA coverage apply to the systems we build and manage on your behalf: intake forms, automated messaging, scheduling, and any PHI that flows through those systems.
This does not replace your practice's own HIPAA obligations — including staff training, internal data handling policies, physical security of your own devices and records, and your Notice of Privacy Practices to patients. HIPAA compliance is a shared responsibility between the technology we build and how your practice operates day to day. We're happy to flag anything on your end that falls outside what our systems cover.
Where we connect your systems to third-party tools (EHR platforms, scheduling software, payment processors), we scope those integrations individually and confirm BAA coverage exists with each connected vendor before any PHI flows through them.
You own your practice's data at all times. If you end services with Kore. Studio, we provide a full export of your contacts, workflows, and associated data as outlined in our Terms of Service.
If you have questions about how a specific system handles PHI, or want documentation of our BAA coverage for your own compliance records, contact us at hello@korestudioco.com.