Security
Security and compliance, taken seriously.
Encryption
PHI encrypted at rest (AES-256) and in transit (TLS 1.3).
Access control
Role-based permissions with an audit log of every access event.
Backups
Daily automated backups, with point-in-time restore on Practice and above.
HIPAA compliance
HIPAA-aligned. BAA available on request.
Data residency
Patient data stored in US-based AWS data centers. Never leaves the US.
Incident response
Documented response process. 72-hour breach notification commitment.