Skip to content

Trust & Security Center

Your health information security is our highest priority

Security Overview

HIPAA-Aligned

Aligned with HIPAA Privacy and Security Rules

Encrypted Data

AES-256 encryption at rest, TLS 1.3 in transit

Audit Trails

Immutable audit logs with hash chain verification

Certifications & Compliance

HIPAA Compliance

Health Insurance Portability and Accountability Act

Full compliance with HIPAA Privacy Rule, Security Rule, and Breach Notification Rule. Annual risk assessments and security audits.

SOC 2 Type II

In Progress

Independent audit of security, availability, processing integrity, confidentiality, and privacy controls.

GDPR-Aligned

European Union Data Protection

Aligned with EU General Data Protection Regulation including right to access, erasure, and data portability.

WCAG 2.1 AA

Web Accessibility Standards

Committed to accessibility with keyboard navigation, screen reader support, and proper contrast ratios.

Security Practices

Authentication & Access Control

  • • Multi-factor authentication (MFA) required for providers and admins
  • • CAPTCHA protection after failed login attempts
  • • Progressive account lockout (1 min → 1 hour)
  • • Session fingerprinting to detect hijacking
  • • Maximum 3 concurrent sessions per user
  • • Automatic session timeout (60 min idle, 24 hr absolute)

Data Protection

  • • AES-256 encryption for data at rest
  • • TLS 1.3 for all data in transit
  • • Field-level encryption for sensitive data (SSN, payment info)
  • • Automated key rotation (90-day cycle)
  • • Secure backup with separate encryption keys

Monitoring & Response

  • • 24/7 security monitoring and alerts
  • • Real-time intrusion detection
  • • Automated breach detection and response
  • • Incident response within 15 minutes
  • • Breach notification within 60 days (HIPAA requirement)

Auditing & Compliance

  • • Immutable audit logs with cryptographic hash chains
  • • All ePHI access logged and monitored
  • • Annual HIPAA training for all staff and providers
  • • Regular penetration testing by external firms
  • • Weekly vulnerability scans

Business Associate Agreements

We maintain signed Business Associate Agreements (BAAs) with all third-party service providers who have access to protected health information (ePHI).

Cloud Infrastructure Provider
Video Consultation Platform
Email Service Provider
AI Analysis Provider

Security Contact

For security inquiries, concerns, or to report a potential vulnerability:

24/7 Security Monitoring

Responsible Disclosure Policy

We welcome security researchers to report vulnerabilities:

  • Submit details via our security report form
  • We'll acknowledge within 24 hours
  • Critical issues patched within 24 hours
  • Recognition on our security hall of fame
Report a vulnerability

Privacy & Data Rights

Your Rights

You have complete control over your health information:

Right to access your data
Right to correct inaccuracies
Right to delete your account
Right to export your data
Right to opt-out of AI features
Right to restrict processing

To exercise any of these rights, use our contact form:

Submit a privacy request

Transparency

0

Data Breaches

(Last 12 months)

100%

Uptime SLA

(Target: 99.9%)

<15min

Incident Response

(Critical issues)

Additional Resources