Security
Security and HIPAA controls
HIPAA has no certification, so here are the controls themselves. Our control set is mapped to the SOC 2 Trust Services Criteria; an independent SOC 2 report has not yet been obtained, and we say so.
| Control | Implementation |
|---|---|
| Business Associate Agreements | PHI is processed only by vendors under a BAA: the cloud provider and the AI model provider. No AI app builders, no unvetted OCR vendors, in the data path. |
| Encryption at rest | Customer-managed KMS keys with annual rotation for storage, backups, logs and secrets, plus application-level encryption of every PHI file. |
| Encryption in transit | TLS 1.2+ on every connection, HTTP redirected to HTTPS, HSTS for one year. |
| Identity | Multi-factor authentication for every user, 12+ character passwords, account lockout after repeated failures, 20-minute idle session timeout. |
| Tenant isolation | Every chart belongs to one facility. Users see only their facility's charts; cross-tenant access is impossible by construction. |
| Audit trail | Every access, verdict, upload and administrative action is written to a hash-chained, tamper-evident log with user, IP and timestamp, retained for more than one year, alongside cloud-level API and network logs. |
| Perimeter | Web application firewall with managed rule sets and rate limiting; intrusion honeypots with automatic IP blocking. |
| Backup and recovery | Encrypted daily backups with 35-day retention and tested restores. |
| Minimum necessary | Patient names never appear in URLs, logs or reports; charts are referenced by anonymous identifiers. Revenue reports contain no patient identifiers. |
| Change control | Versioned source control, automated tests including a frozen-rubric guard, and infrastructure defined as code. |
Questions from your compliance officer are welcome: raj@precisionpainandrehab.com.