We handle protected health information, so this page states our posture directly rather than in badges.
How patient data is handled
- Encryption in transit and at rest.
- Role-based access control, so a user sees the records their role requires and not the rest.
- Audit logging of access and of every clinical decision, attributable to an individual user.
- Business Associate Agreements with the vendors that touch PHI on our behalf, including any AI-assisted tooling.
- Tenant separation, so one client’s records are not visible to another.
- Credentials held encrypted rather than in plain configuration.
What we do not claim
We do not advertise a SOC 2 report we have not completed, and you will not find that badge on this site. Several vendors in this market display audit logos they cannot produce a report for; ask any of them, including us, for the document rather than the image.
We also do not describe ourselves as “HIPAA certified”, because no such certification exists. HIPAA compliance is a posture and a set of agreements, not a certificate.
What we will give you in diligence
- A signed Business Associate Agreement.
- A description of the data flows for your specific integration.
- Our subprocessor position for anything that touches your patients’ records.
- Confirmation of what is retained, for how long, and what happens on termination.
Related
Book a call and we will walk your technical reviewer through it.