Designed around privacy and tenant separation.
Security is a design constraint here, not an afterthought. The posture below describes how the platform is built — details are reviewed with our compliance team.
How it is protected
Infrastructure & network
Data is encrypted in transit and at rest, and each clinic runs on dedicated, isolated infrastructure — no shared database rows across tenants.
Application & access control
Role-based access, per-tenant isolation enforced in the application layer, and an audit log of every access to a record — so you can answer "who saw what, when."
Compliance & data handling
A Business Associate Agreement is executed before any patient data moves, and our subprocessor list is available on request.
Compliance posture
- HIPAAEngineered around the Privacy & Security Rules
- BAAExecuted before any patient data moves
- SOC 2Controls aligned to SOC 2 principles
- HITRUSTMapped to the HITRUST CSF control set
Subprocessors
We maintain a list of the subprocessors that help operate the platform. The current list is available to clinics on request and in your Business Associate Agreement.
Security & privacy FAQ
Is patient data isolated between clinics?
Yes. Each clinic runs on its own isolated tenant infrastructure, and the application layer enforces that a clinic can only ever see its own records. Isolation is verified with cross-tenant tests.
Do you sign a BAA?
Yes. A Business Associate Agreement is executed before any patient data is stored or moves through the platform.
Is access to records logged?
Yes. Every access to a record is written to an audit log that is reviewable, so a clinic can account for who accessed what and when.
Where can I see your subprocessors?
The current subprocessor list is available to clinics on request and is referenced in your Business Associate Agreement.
Ready to give your clinic a remote-monitoring program?
Pick a plan and start a 14-day free trial, or talk to our team first.