Security

Security and HIPAA controls

HIPAA has no certification, so here are the controls themselves. Our control set is mapped to the SOC 2 Trust Services Criteria; an independent SOC 2 report has not yet been obtained, and we say so.

ControlImplementation
Business Associate AgreementsPHI is processed only by vendors under a BAA: the cloud provider and the AI model provider. No AI app builders, no unvetted OCR vendors, in the data path.
Encryption at restCustomer-managed KMS keys with annual rotation for storage, backups, logs and secrets, plus application-level encryption of every PHI file.
Encryption in transitTLS 1.2+ on every connection, HTTP redirected to HTTPS, HSTS for one year.
IdentityMulti-factor authentication for every user, 12+ character passwords, account lockout after repeated failures, 20-minute idle session timeout.
Tenant isolationEvery chart belongs to one facility. Users see only their facility's charts; cross-tenant access is impossible by construction.
Audit trailEvery access, verdict, upload and administrative action is written to a hash-chained, tamper-evident log with user, IP and timestamp, retained for more than one year, alongside cloud-level API and network logs.
PerimeterWeb application firewall with managed rule sets and rate limiting; intrusion honeypots with automatic IP blocking.
Backup and recoveryEncrypted daily backups with 35-day retention and tested restores.
Minimum necessaryPatient names never appear in URLs, logs or reports; charts are referenced by anonymous identifiers. Revenue reports contain no patient identifiers.
Change controlVersioned source control, automated tests including a frozen-rubric guard, and infrastructure defined as code.

Questions from your compliance officer are welcome: raj@precisionpainandrehab.com.