Security
Data Protection & Security.
Encryption at rest
All stored PHI is encrypted with AES-256. Sensitive environments are segregated with independent keys, access controls, and monitoring.
Encryption in transit
All data in motion uses TLS 1.2 or higher. Mutual TLS is used for system-to-system integrations with health plan partners.
Key management
Encryption keys are stored in Hardware Security Modules (HSMs) and accessed only by authorized personnel under multi-factor authentication.
File system security
Files containing PHI use FIPS 140-2 validated algorithms. Role-based permissions are audited, and secure deletion protocols prevent forensic recovery.
Storage media
All storage hardware uses self-encrypting drive technology. Decommissioned media is wiped to NIST 800-88 standards or physically destroyed.
Monitoring & audit
Continuous monitoring with 24/7 security operations. All PHI access is logged and reviewed for anomalies.

