Security & Compliance
GDPR · HIPAA · FHIR
Standards ROOK works with
- GDPR
- HIPAA
- FHIR
ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor.
Standards
ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor.

The EU regulation on how personal data is collected, processed and stored. ROOK processes EU personal data under GDPR as a data processor.
Talk to our team
The US standard for protecting health information. ROOK operates under a HIPAA-aligned security program and signs BAAs with covered entities.
Request a BAA
The HL7 standard for exchanging healthcare data between systems. ROOK supports FHIR-based interoperability for clinical-data workflows, with FHIR R4 output for lab data.
Explore Lab Data APIGDPR · HIPAA · FHIR
Standards ROOK works with
ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor.
ROOK is categorized as "Medical testing services, namely, fitness evaluation".
Safeguards
Each card shows its safeguard at work on a sample record.
UUID-based architecture
ROOK uses a UUID-based architecture to pseudonymize user data, reducing direct identifiability and minimizing exposure.
At rest and in transit
Protected data is encrypted both at rest and in transit, so it stays unreadable to anyone without access.
Least privilege, need-to-know
Role-based access controls let only authorized users reach protected data, following least privilege and need-to-know principles.
Multi-layered security
ROOK runs on a secure, scalable cloud infrastructure with multi-layered security protocols around the data.
For your review
Agreements and policies your legal and security teams can check before you integrate. ROOK's API is also designed to support CCPA and CPRA requirements.

HIPAA
For implementations that handle protected health information. ROOK signs BAAs with covered entities as part of the implementation.
Request a BAA
GDPR
For processing personal data under GDPR. ROOK supports it with a Data Processing Agreement.
Request a DPALast updated May 28, 2026
What personal data ROOK collects, and how it is processed and disclosed.
Read the policyLast updated August 2026
Last updated June 3, 2026



Nothing matches that search.
Compliance
Talk to our team about BAAs, DPAs and the security documentation your review needs.
FAQ
The standards, safeguards and agreements behind every ROOK integration.
ROOK operates under a HIPAA-aligned security program, signs BAAs with covered entities, and processes EU personal data under GDPR as a data processor. ROOK’s API is also designed to support CCPA and CPRA requirements.
Yes. For implementations that handle protected health information, ROOK signs BAAs with covered entities as part of the implementation.
Yes. For processing personal data under GDPR, ROOK supports it with a Data Processing Agreement.
ROOK uses a UUID-based architecture to pseudonymize user data, encrypts protected data at rest and in transit, applies role-based access controls following least privilege and need-to-know principles, and runs on a secure, scalable cloud infrastructure with multi-layered security protocols.
The Business Associate Agreement, the Data Processing Agreement, the privacy policy, the terms for ROOK services and the cookies policy.
No questions match that yet. Try another word or topic.