Built to follow healthcare industry security and privacy standards
Full compliance with the Health Insurance Portability and Accountability Act. We protect PHI with the highest standards.
Security controls designed to meet SOC 2 standards for service organizations, covering security, availability, and confidentiality.
Designed with 42 CFR Part 2 standards in mind, providing additional privacy protections for substance use disorder treatment records.
Transparent risk assessment reflecting our commitment to protecting sensitive healthcare data
Data Access Level
Restricted
Access to sensitive data is tightly controlled and limited to authorized personnel only.
Impact Level
Severe
We recognize the critical nature of healthcare data and maintain the highest protection standards.
Recovery Time Objective
Immediate
Our systems are designed for immediate recovery to ensure zero downtime for critical operations.
Multi-layered security controls protecting every aspect of our platform
Comprehensive audit trails for all system access, data modifications, and administrative actions.
AES-256 encryption at rest and TLS 1.3 in transit for all sensitive data.
Required MFA for all system access and admin functions.
Granular permissions ensure minimum necessary access at every level.
Real-time monitoring of all access events with automated alerting for anomalies.
Formal vulnerability disclosure program for ethical reporting of security issues.
Enterprise-grade infrastructure with continuous monitoring and physical safeguards
Best-in-class infrastructure providers with enterprise-grade secure computing and storage.
Corporate network protected against external and internal threats with defense-in-depth.
Industry best practices for endpoint security across all company devices.
Systems continuously monitored for security threats and vulnerabilities 24/7.
Access monitoring, alarm systems, surveillance, and controlled alternate work sites.
Quarterly penetration testing, security assessments, and self-assessment questionnaires.
Comprehensive policies, processes, and teams dedicated to maintaining security at every level
Internal measures and practices to maintain a high standard of organizational security.
Dedicated team responding to security incidents with defined playbooks and escalation procedures.
Dedicated team managing security risks with ongoing assessment and mitigation strategies.
Strict asset management policies ensuring all assets are inventoried, tracked, and secure.
Business continuity plan ensuring continued operations in the event of a disaster.
Changes are properly reviewed, approved, and documented through a formal process.
Our AI systems are built with security-first principles. We maintain strict data handling protocols for all AI interactions, ensuring patient information is never used for model training without explicit consent. All AI-generated outputs are monitored, logged, and subject to the same compliance standards as human interactions.
Compliance is not just a checkbox, it's embedded in our culture and operations
All team members complete security awareness and HIPAA training to ensure best practices.
We sign Business Associate Agreements with all clients handling protected health information.
Dedicated compliance officers ensure ongoing adherence to all regulatory requirements.
Environmental, social, and governance considerations are embedded in our operations and decisions.
Customer data privacy is top of mind. We follow industry best practices and all applicable regulations.
Legal counsel reviews all commercial activities. We take legal matters seriously at every level.
Start your security review, view and download documentation, and request access to detailed security reports and self-assessments.