COMPLIANCE & SECURITY
Built for the audit that hasn't happened yet
Security and compliance are designed in, not bolted on. Here is what your compliance officer will want to see.
HEALTHCARE-GRADE BY DESIGN
Protection at every layer
HIPAA & HITECH
PHI protected end to end, with immutable audit logging retained for six years.
42 CFR Part 2
Substance-use and psychotherapy records suppressed from billing without consent.
NCQA & TJC alignment
Credentialing aligned to recognised standards, including FPPE and OPPE monitoring.
OIG / SAM & NPDB
Monthly federal sanctions screening and NPDB queries guard against exclusion risk.
Zero-Trust cloud
Hosted on a Zero-Trust cloud with enforced MFA and fully managed devices.
Isolated per-clinic cloud
Each clinic runs in its own Google Cloud project - one practice can never reach another.
Encrypted, tamper-proof
Customer-managed encryption keys and write-once storage so records can't be altered.
FWA program
A formal Fraud, Waste & Abuse program with monthly audits guards against OIG risk.
No BAA, no access. A signed Business Associate Agreement is in place before any patient data flows. Your data is always yours - recoverable, portable, and securely decommissioned if you ever leave.
Have a security questionnaire
Send it over - we'll complete it and walk your team through our controls.