Security

Data Protection & Security.

Our methodologies, protocols, and systems for protecting patient information at rest and in transit—aligned with HIPAA, HITECH, and applicable state regulations.

Encryption at rest

All stored PHI is encrypted with AES-256. Sensitive environments are segregated with independent keys, access controls, and monitoring.

Encryption in transit

All data in motion uses TLS 1.2 or higher. Mutual TLS is used for system-to-system integrations with health plan partners.

Key management

Encryption keys are stored in Hardware Security Modules (HSMs) and accessed only by authorized personnel under multi-factor authentication.

File system security

Files containing PHI use FIPS 140-2 validated algorithms. Role-based permissions are audited, and secure deletion protocols prevent forensic recovery.

Storage media

All storage hardware uses self-encrypting drive technology. Decommissioned media is wiped to NIST 800-88 standards or physically destroyed.

Monitoring & audit

Continuous monitoring with 24/7 security operations. All PHI access is logged and reviewed for anomalies.