Skip to content

Trust

We hold ourselves to what we check for you.

No borrowed logos or certifications we don’t have. Here’s what we actually do.

Phishing-resistant sign-in

Staff accounts use phishing-resistant multi-factor authentication (passkeys or security keys).

Managed, monitored devices

Company devices are centrally managed and monitored by our own security tooling.

Security monitoring

We run a SIEM/XDR that collects and alerts on security events across our systems.

Evidence retention

Client evidence is stored in write-once storage with a six-year retention lock.

BAAs where PHI is shared

We sign a business associate agreement with every client that shares protected health information with us.

Patient data stays put

We design our systems so patient data isn’t sent to outside AI services, and sanitize anything processed beyond our own systems.

Report a security issue

Found a vulnerability or have a security question? Email griff@hipaa.inc. We’ll acknowledge it and keep you updated.