Security
HIPAA-eligible infrastructure, encrypted data at rest and in transit, audit logs on every clinical action. Built with HIPAA-aware workflows for the security reviews that come with real revenue.
Encryption and storage
Audit log
Infrastructure
Eligible
Type II · in progress
Available on Growth+
Data residency
Posture
GCM-mode at rest, per-row IVs. Keys rotated every 90 days.
All client and inter-service traffic uses modern TLS only.
Every clinical action recorded. PII scrubbed. 7-year retention.
Provider, practitioner, front desk, admin. Permissions enforced server-side.
SAML and OIDC support shipping Q4 on the Enterprise tier.
TOTP and recovery codes available today. WebAuthn next.
Sub-processors
No hidden vendors. Every party that handles PHI is named here, with the role they play and BAA status shown by vendor.
| Sub-processor | Role | Region | BAA |
|---|---|---|---|
| Stripe | Payments and Connect onboarding | US | Executed |
| Resend | Transactional email | US | Executed |
| Twilio | SMS and 10DLC messaging | US | Executed |
| OpenAI | Voice transcription via Whisper | US-only API | Executed |
| Supabase | Managed Postgres and auth | US | In progress |
| Vercel | Hosting and edge | Global, US data plane | Executed |
✦ Patient data never leaves US borders by default
Compliance
We respond to security questionnaires and BAA requests inside one business day. Most clinics clear review on the first pass.