Security & Compliance
Built for organizations where compliance is not optional.
Health plans and providers operate under HIPAA and regulator scrutiny. Here is how we approach security in our engagements — and how this website itself handles data.
How we work in your environment
- Business Associate Agreements: we execute BAAs when engagements involve access to PHI.
- Least-privilege access: we request the minimum access needed, through your identity systems (Azure AD / Entra), and support MFA and audited accounts.
- Data stays in your environment: our default is to work inside your infrastructure — your servers, your Azure tenant, your VPN — rather than moving data out.
- HIPAA-aware engineering: integrations and automations are designed with PHI handling, minimum-necessary principles, and audit trails in mind.
- Documentation & handoff: access lists, credentials handling, and system documentation are part of every engagement's deliverables.
Infrastructure practices
- Azure-based environments with network segmentation, firewalling, and secure remote access
- Encryption in transit (TLS) and at rest for data stores we design
- Backup, recovery, and retention strategies appropriate to regulated data
- Security baselines for Microsoft 365 and identity (SSO/MFA)
This website's own data practices
We believe a security page should also disclose what the site you're reading collects:
- The chat assistant logs conversations (questions and answers) to help us respond and improve the service. Please don't share PHI or confidential information in the chat.
- We use analytics to understand page usage (pages viewed, general interaction events).
- The contact form stores the information you submit so we can respond.
- Details are in our privacy policy.
Questions?
Security reviews and questionnaires are a normal part of working with health plans — we're glad to walk your security team through our practices. Contact us.