Security Architecture & compliance
Latest Review: January 2026 | HIPAA Technical Safeguards Verified
1. HIPAA Security Rule Alignment
Our infrastructure is built specifically to address the technical safeguards under the HIPAA Security Rule (45 CFR § 164.312). We ensure the confidentiality, integrity, and availability of all Protected Health Information (PHI) created, received, maintained, or transmitted by our system.
2. Data Encryption Standards
- In Transit: All data transmissions, including EHR REST payloads and HL7 synchronization streams, are encrypted using TLS 1.3 with strong cipher suites. Older, deprecated protocols (SSL 3.0, TLS 1.0, 1.1) are disabled at the edge.
- At Rest: Physical database disks and file stores housing patient demographics or coding charts are encrypted using AES-256. Cryptographic keys are managed securely and rotated automatically every 90 days.
3. Access Control & Clinical Audit Logging
We protect billing data from unauthorized access through multi-layered network and logical authentication:
- MFA Mandatory: Access to the billing engine is restricted to authenticated billers and credentials audited via Multi-Factor Authentication (MFA).
- Audit Logs (HITECH Compliance): Detailed database audit logs record all queries, reads, updates, and transmissions of patient records. These logs are stored in write-once-read-many (WORM) storage, preventing tamper or deletion.
4. SOC 2 & Clearinghouse Gateway Certifications
Our server host centers maintain SOC 2 Type II certifications. All claims are transmitted to payers through secure clearinghouses certified under the CAQH CORE guidelines, ensuring reliable eligibility verification and ERA remittance routing.
