HIPAA compliance
A snapshot of administrative, physical and technical safeguards mapped to 45 CFR §164. Toggle policy switches to enforce them across the network.
Practitioners see their clinic; patients see their own chart; admins see the network. Enforced at the database with Row Level Security.
Every privileged action is recorded with actor, target, and timestamp. 7-year retention. CSV export for review.
Clinical notes are signed; outcomes records carry a hash. Tampering invalidates the signature.
TLS 1.3 in transit. HSTS preload. Certificate pinning for mobile.
AES-256 disk encryption on Postgres and object storage. KMS-managed keys.
Require multi-factor authentication for every practitioner, staff, and admin account.
Sessions terminate after 15 minutes of inactivity on clinical surfaces.
Patients can download their full record (sessions, outcomes, notes) in machine-readable format on request.
BAAs on file with all sub-processors (database, storage, email, telemetry).