Trust & Security Center
Your health information security is our highest priority
Security Overview
HIPAA-Aligned
Aligned with HIPAA Privacy and Security Rules
Encrypted Data
AES-256 encryption at rest, TLS 1.3 in transit
Audit Trails
Immutable audit logs with hash chain verification
Certifications & Compliance
HIPAA Compliance
Health Insurance Portability and Accountability Act
Full compliance with HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Annual risk assessments and security audits.
SOC 2 Type II
In Progress
Independent audit of security, availability, processing integrity, confidentiality, and privacy controls.
GDPR-Aligned
European Union Data Protection
Aligned with EU General Data Protection Regulation including right to access, erasure, and data portability.
WCAG 2.1 AA
Web Accessibility Standards
Committed to accessibility with keyboard navigation, screen reader support, and proper contrast ratios.
Security Practices
Authentication & Access Control
- • Multi-factor authentication (MFA) required for providers and admins
- • CAPTCHA protection after failed login attempts
- • Progressive account lockout (1 min → 1 hour)
- • Session fingerprinting to detect hijacking
- • Maximum 3 concurrent sessions per user
- • Automatic session timeout (60 min idle, 24 hr absolute)
Data Protection
- • AES-256 encryption for data at rest
- • TLS 1.3 for all data in transit
- • Field-level encryption for sensitive data (SSN, payment info)
- • Automated key rotation (90-day cycle)
- • Secure backup with separate encryption keys
Monitoring & Response
- • 24/7 security monitoring and alerts
- • Real-time intrusion detection
- • Automated breach detection and response
- • Incident response within 15 minutes
- • Breach notification within 60 days (HIPAA requirement)
Auditing & Compliance
- • Immutable audit logs with cryptographic hash chains
- • All ePHI access logged and monitored
- • Annual HIPAA training for all staff and providers
- • Regular penetration testing by external firms
- • Weekly vulnerability scans
Business Associate Agreements
We maintain signed Business Associate Agreements (BAAs) with all third-party service providers who have access to protected health information (ePHI).
Security Contact
For security inquiries, concerns, or to report a potential vulnerability:
Responsible Disclosure Policy
We welcome security researchers to report vulnerabilities:
- •Submit details via our security report form
- •We'll acknowledge within 24 hours
- •Critical issues patched within 24 hours
- •Recognition on our security hall of fame
Privacy & Data Rights
Your Rights
You have complete control over your health information:
To exercise any of these rights, use our contact form:
Submit a privacy requestTransparency
Data Breaches
(Last 12 months)
Uptime SLA
(Target: 99.9%)
Incident Response
(Critical issues)