COMPLIANCE & SECURITY

Built for the audit that hasn't happened yet

Security and compliance are designed in, not bolted on. Here is what your compliance officer will want to see.

HEALTHCARE-GRADE BY DESIGN

Protection at every layer

HIPAA & HITECH

PHI protected end to end, with immutable audit logging retained for six years.

42 CFR Part 2

Substance-use and psychotherapy records suppressed from billing without consent.

NCQA & TJC alignment

Credentialing aligned to recognised standards, including FPPE and OPPE monitoring.

OIG / SAM & NPDB

Monthly federal sanctions screening and NPDB queries guard against exclusion risk.

Zero-Trust cloud

Hosted on a Zero-Trust cloud with enforced MFA and fully managed devices.

Isolated per-clinic cloud

Each clinic runs in its own Google Cloud project - one practice can never reach another.

Encrypted, tamper-proof

Customer-managed encryption keys and write-once storage so records can't be altered.

FWA program

A formal Fraud, Waste & Abuse program with monthly audits guards against OIG risk.

No BAA, no access. A signed Business Associate Agreement is in place before any patient data flows. Your data is always yours - recoverable, portable, and securely decommissioned if you ever leave.

Have a security questionnaire

Send it over - we'll complete it and walk your team through our controls.