Service Status: All Systems Operational — Safeguarded by our multi-cloud infrastructure.
HIPAA-compliant Enterprise workflows · Separate BAA required

HIPAA-compliant Enterprise Sex Offender Registry API

Offenders.io supports HIPAA-compliant Enterprise workflows for approved healthcare customers under a separately executed Business Associate Agreement. Healthcare systems, SNFs, home health teams, and compliance platforms can use an approved Enterprise endpoint to run source-verified registry screening against official public records across all 50 states, territories, and tribes.

BAASeparate agreement
900K+Registry records
TLSEncrypted transit
<200msTypical responses
Ask AI about Offenders.io

HIPAA-compliant Enterprise workflows for healthcare screening

Purpose-built access patterns for regulated healthcare teams that need registry screening without pushing PHI through standard self-service channels.

📜

Separate BAA

HIPAA-compliant access requires a separately executed Business Associate Agreement and Enterprise approval.

🔒

Approved endpoint

Enterprise customers use an approved workflow and endpoint; standard public API endpoints are not for PHI or ePHI.

🔐

Encrypted transit

API traffic is encrypted in transit. Request telemetry is minimized and sanitized for operational monitoring.

📋

SOC 2 aligned controls

Controls are designed around security, availability, confidentiality, access review, and change management.

👥

Minimum necessary

Only the search inputs needed for the approved workflow should be transmitted.

🌐

Official public records

Returned registry records come from official public sources and are not clinical advice or medical determinations.

How HIPAA-compliant Enterprise access works

The standard API is fast to evaluate. HIPAA-compliant production use requires Enterprise review first.

1

Review the workflow

Tell us what data you plan to send, where it originates, and whether PHI or ePHI is involved.

2

Execute the BAA

Approved Enterprise customers sign a separate BAA before transmitting regulated data.

3

Use approved access

We provision the agreed Enterprise workflow and keep support channels free of PHI/ePHI.

4

Validate and monitor

Use request IDs, sanitized telemetry, and documented controls for support and audit review.

Built for healthcare and compliance teams

HIPAA-compliant sex offender API workflows are available for Enterprise customers who need BAA-backed registry screening.

🏥

Skilled nursing facilities

Pre-admission and compliance screening where state rules require sex offender registry checks.

🏠

Home health agencies

Registry screening for workflows involving vulnerable populations and in-home care operations.

🏛

Hospitals and health systems

Enterprise registry checks that can fit into credentialing, compliance, or safety workflows.

🩹

Behavioral health providers

Screening support for regulated residential and patient-safety workflows.

💻

Healthcare platforms

API-first access for compliance software teams that need a BAA-backed vendor workflow.

📊

Multi-site operators

Batch and API workflows for teams managing many facilities or high-volume screening needs.

What is and is not HIPAA-compliant

Clear boundaries help customers avoid sending regulated data through the wrong path.

Channel or tierHIPAA-compliant?Boundary
Enterprise workflow with executed BAAYesApproved workflow only, under the signed agreement
Self-service or On Demand APINoNo BAA; do not submit PHI or ePHI
Free trial or test keyNoEvaluation only; no regulated data
Dashboard, support, email, chatNoNever send PHI/ePHI through support channels
Registry records returned by the APIN/AOfficial public-record data, not medical advice

If your workflow may involve PHI or ePHI, contact us before sending production traffic.

HIPAA-compliant API FAQ

Is Offenders.io HIPAA-compliant?

Offenders.io supports HIPAA-compliant Enterprise workflows only for approved customers under a separately executed BAA. Self-service, free trial, and standard API accounts are not HIPAA-compliant workflows and must not transmit PHI or ePHI.

Is a BAA included with standard API pricing?

No. BAA access is available only for approved Enterprise customers under a separately executed Business Associate Agreement.

Do healthcare customers use a different endpoint?

Yes. HIPAA-compliant Enterprise workflows use an approved access path. Standard public API endpoints are for non-PHI evaluation and regular non-HIPAA use cases.

Is sex offender registry data PHI?

No. Registry results returned by Offenders.io are sourced from official public records. They are not medical information, not medical advice, and not a clinical determination.

Can I test data quality before Enterprise review?

Yes. You can evaluate data quality with a standard test or self-service key, but do not send PHI or ePHI until a BAA is executed and the approved Enterprise workflow is provisioned.

Request HIPAA-compliant Enterprise access

Tell us about your healthcare workflow. We will review BAA eligibility and the approved API path before production use.

Contact Us →Review BAA Template