Security & Compliance

Built for organizations where compliance is not optional.

Health plans and providers operate under HIPAA and regulator scrutiny. Here is how we approach security in our engagements — and how this website itself handles data.

How we work in your environment

  • Business Associate Agreements: we execute BAAs when engagements involve access to PHI.
  • Least-privilege access: we request the minimum access needed, through your identity systems (Azure AD / Entra), and support MFA and audited accounts.
  • Data stays in your environment: our default is to work inside your infrastructure — your servers, your Azure tenant, your VPN — rather than moving data out.
  • HIPAA-aware engineering: integrations and automations are designed with PHI handling, minimum-necessary principles, and audit trails in mind.
  • Documentation & handoff: access lists, credentials handling, and system documentation are part of every engagement's deliverables.

Infrastructure practices

  • Azure-based environments with network segmentation, firewalling, and secure remote access
  • Encryption in transit (TLS) and at rest for data stores we design
  • Backup, recovery, and retention strategies appropriate to regulated data
  • Security baselines for Microsoft 365 and identity (SSO/MFA)

This website's own data practices

We believe a security page should also disclose what the site you're reading collects:

  • The chat assistant logs conversations (questions and answers) to help us respond and improve the service. Please don't share PHI or confidential information in the chat.
  • We use analytics to understand page usage (pages viewed, general interaction events).
  • The contact form stores the information you submit so we can respond.
  • Details are in our privacy policy.

Questions?

Security reviews and questionnaires are a normal part of working with health plans — we're glad to walk your security team through our practices. Contact us.