CollaboPointCollaboPoint
For clinical & research teams

BAA-ready architecture — and a straight answer about what that means

Administrative and research collaboration for practices, labs and health teams: encryption at rest, audit logging, MFA and role-based access. We have not signed a BAA yet, so this page starts with what we cannot do.

Start freeSee pricing

No card required · Free plan doesn't expire · Set up in minutes

Sound familiar?

If more than one of these lands, the tool sprawl is costing you more than the subscriptions do.

  • Clinical and research documents get shared through consumer tools because the approved option is unusable.
  • Nobody can produce a reliable record of who accessed a given file, and when.
  • Meeting and document tools are separately licensed, separately administered and separately reviewed.
  • Every vendor claims to be "HIPAA compliant" and few will explain precisely what they mean by it.

What you get on day one

Everything below works today. What doesn't, we list further down.

Encryption at rest and in transit

AES-256 at rest, TLS 1.3 in transit, including chat message bodies. Keys are managed by us, so this is encryption at rest — not end-to-end encryption.

Audit logging

Admin-readable record of document access, membership changes and security events such as sign-ins and MFA changes.

Role-based access

Owner, admin, member and guest roles, scoped per workspace, enforced server-side rather than in the interface alone.

Multi-factor authentication

TOTP and email one-time codes on every plan, not restricted to an enterprise tier.

Secure calls and screen share

HD calls with screen sharing for internal case discussion, teaching and administrative meetings.

Document viewing

Built-in PDF viewing with annotation for protocols, reports and administrative paperwork.

What a 20-person team pays

Same work, two bills. Published list prices, not our estimates.

ToolReplaced byPer seat/mo
Notion BusinessDocuments and protocols£18.00
Slack Business+Team channels£12.00
Zoom BusinessInternal calls and screen share£18.00
Their stack20 seats£48.00 · £960.00/mo
CollaboPoint BusinessAll of the above£14.00 · £280.00/mo

You keep about £680 a month — £8160 a year.

Comparison uses each vendor's published list price for a comparable paid tier, 2026, per user per month. Competitor pricing changes and may differ with annual or volume terms — treat this as an illustration, not a quote.

What we don't have yet

You would find these in a procurement review anyway. Here they are up front, with where each one stands.

Signed Business Associate Agreement

Not signed

We have not signed a BAA. Do not place protected health information in CollaboPoint on the strength of this page. Signing is targeted for late 2026 / early 2027, following legal review.

HIPAA certification

Does not exist

There is no such thing as HIPAA certification — any vendor claiming one is describing something else. What we offer today is the technical architecture a BAA would rest on.

SOC 2 Type II

Not audited

Our hosting provider is certified; CollaboPoint itself has not completed its own audit.

HL7 / FHIR & EHR integration

Not built

No clinical-system integrations are available.

Medical imaging

Out of scope

Nothing beyond ordinary PDF viewing. This is not a diagnostic tool and is not a medical device.

Questions

Are you HIPAA compliant?

No, and we would be misleading you if we said yes. HIPAA compliance is a property of how a covered entity operates, underpinned by a signed Business Associate Agreement — and we have not signed one. Our architecture is built to support a BAA (encryption at rest, audit logging, access controls, MFA), which is why we describe it as BAA-ready. Until a BAA is signed, CollaboPoint should not hold protected health information.

What can we legitimately use it for today?

Work that does not involve protected health information: internal administrative collaboration, research that uses de-identified or non-patient data, teaching material, protocols, policies, rotas and operational documents.

When will a BAA be available?

Targeted for late 2026 or early 2027, subject to legal review. We are not going to promise a date we cannot control. If a BAA is a hard requirement for you now, we are not the right choice yet — and we would rather tell you that than take the pilot.

Can we start a conversation before the BAA exists?

Yes. We are happy to walk your security or compliance team through the architecture, share our data processing addendum and sub-processor list, and answer questions on the record so you can evaluate us properly when the BAA does land.

Try it with your own team

The free plan is genuinely free — no card, no trial countdown. Invite a couple of colleagues and see whether it sticks.

Create your workspace