Built for the rules you answer to

The standards ROOK follows, the safeguards around every record and the agreements your review needs, in one place.

Standards

The standards behind every ROOK integration.

ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor.

  • GDPR badge

    GDPRGeneral Data Protection Regulation

    • EU & EEA
    • Personal data
    • Privacy

    The EU regulation on how personal data is collected, processed and stored. ROOK processes EU personal data under GDPR as a data processor.

    Talk to our team
  • HIPAA badge

    HIPAAHealth Insurance Portability and Accountability Act

    • United States
    • Health information
    • BAA available

    The US standard for protecting health information. ROOK operates under a HIPAA-aligned security program and signs BAAs with covered entities.

    Request a BAA
  • FHIR badge

    FHIRFast Healthcare Interoperability Resources

    • HL7 standard
    • Interoperability
    • R4 output

    The HL7 standard for exchanging healthcare data between systems. ROOK supports FHIR-based interoperability for clinical-data workflows, with FHIR R4 output for lab data.

    Explore Lab Data API

Security & Compliance

GDPR · HIPAA · FHIR

Talk to our team

Standards ROOK works with

  • GDPR
  • HIPAA
  • FHIR

ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor.

ROOK is categorized as "Medical testing services, namely, fitness evaluation".

Safeguards

Four safeguards protect the data ROOK handles.

Each card shows its safeguard at work on a sample record.

  • Pseudonymized data

    UUID-based architecture

    • UUID-based
    • Less identifiable

    ROOK uses a UUID-based architecture to pseudonymize user data, reducing direct identifiability and minimizing exposure.

  • Data encryption

    At rest and in transit

    • At rest
    • In transit

    Protected data is encrypted both at rest and in transit, so it stays unreadable to anyone without access.

  • Access controls

    Least privilege, need-to-know

    • Role-based
    • Least privilege

    Role-based access controls let only authorized users reach protected data, following least privilege and need-to-know principles.

  • Cloud infrastructure

    Multi-layered security

    • Scalable
    • Multi-layered

    ROOK runs on a secure, scalable cloud infrastructure with multi-layered security protocols around the data.

For your review

Every document your compliance review asks for.

Agreements and policies your legal and security teams can check before you integrate. ROOK's API is also designed to support CCPA and CPRA requirements.

  • HIPAA badge

    Business Associate Agreement

    HIPAA

    • United States
    • Health information
    • BAA available

    For implementations that handle protected health information. ROOK signs BAAs with covered entities as part of the implementation.

    Request a BAA
  • GDPR badge

    Data Processing Agreement

    GDPR

    • EU & EEA
    • Personal data
    • DPA available

    For processing personal data under GDPR. ROOK supports it with a Data Processing Agreement.

    Request a DPA
  • Privacy policy

    Last updated May 28, 2026

    • Policy
    • 13 sections

    What personal data ROOK collects, and how it is processed and disclosed.

    Read the policy
  • Terms for ROOK services

    Last updated August 2026

    • Terms
    • 14 sections

    The agreement behind ROOK Connect, its APIs, SDKs and webhooks.

    Read the terms
  • Cookies policy

    Last updated June 3, 2026

    • Policy
    • 5 sections

    How the ROOK website uses cookies, and how to manage them.

    Read the policy

Articles on compliance from the ROOK blog

Compliance

Start building on secure health data.

Talk to our team about BAAs, DPAs and the security documentation your review needs.

FAQ

Frequently asked questions about ROOK compliance

The standards, safeguards and agreements behind every ROOK integration.

Which compliance standards does ROOK follow?

ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor. ROOK’s API is also designed to support CCPA and CPRA requirements.

Does ROOK sign a Business Associate Agreement?

Yes. For implementations that handle protected health information, ROOK signs BAAs with covered entities as part of the implementation.

Does ROOK offer a Data Processing Agreement?

Yes. For processing personal data under GDPR, ROOK supports it with a Data Processing Agreement.

How does ROOK protect the data it handles?

ROOK uses a UUID-based architecture to pseudonymize user data, encrypts protected data at rest and in transit, applies role-based access controls following least privilege and need-to-know principles, and runs on a secure, scalable cloud infrastructure with multi-layered security protocols.

Which documents can my team review before integrating?

The Business Associate Agreement, the Data Processing Agreement, the privacy policy, the terms for ROOK services and the cookies policy.

Still have questions?Our team can review your sources and use case with you.
Schedule a demo

Newsletter

Stay in the loop.

Sign up with your email address to receive news and updates from the ROOK team.

We respect your privacy. Read our privacy policy.