Trust
We hold ourselves to what we check for you.
No borrowed logos or certifications we don’t have. Here’s what we actually do.
Phishing-resistant sign-in
Staff accounts use phishing-resistant multi-factor authentication (passkeys or security keys).
Managed, monitored devices
Company devices are centrally managed and monitored by our own security tooling.
Security monitoring
We run a SIEM/XDR that collects and alerts on security events across our systems.
Evidence retention
Client evidence is stored in write-once storage with a six-year retention lock.
BAAs where PHI is shared
We sign a business associate agreement with every client that shares protected health information with us.
Patient data stays put
We design our systems so patient data isn’t sent to outside AI services, and sanitize anything processed beyond our own systems.
Report a security issue
Found a vulnerability or have a security question? Email griff@hipaa.inc. We’ll acknowledge it and keep you updated.