Security & certification
Where we actually are, not where a badge implies we are.
We'd rather tell you exactly what's done, what's in progress, and what isn't started than let a page full of logos imply more than is true. Certification-status misrepresentation is a real, enforced problem in this market — the OIG has pursued civil penalties for it, and several incumbents carry DOJ settlements over exactly this. We're not going to be a case study in that.
ONC Health IT Certification
In progressWe are building to the full HTI-1 scope — Base EHR definition, e-prescribing/EPCS, patient API, and EHI export — sized to the actual product, not a narrower pass done twice. We are not yet certified, and we will say so plainly until we are.
HIPAA Security Rule
Built to, ahead of scheduleRead-auditing on every data access, field-level minimum-necessary access, server-enforced auto-logoff, and encryption at rest and in transit — built to the tighter posture proposed in the 2027 NPRM, not just the current rule.
SOC 2 Type II
Controls in progressWe are going straight to Type II — no Type I detour — with control implementation running alongside infrastructure build-out so the observation window isn’t the bottleneck.
State privacy law
Built to the strictest stateOur authorization and disclosure workflows are built to California’s CMIA as the ceiling, which covers the rest of the country by superset, with a separate check against Washington’s My Health My Data Act for any non-PHI consumer data our patient portal collects.
Business Associate Agreements
Standard, not a negotiationA BAA is available to every customer handling real patient data, as a matter of course — not an enterprise-tier add-on.
Demo environments
Enforced, not just promisedOur public demo environment can never hold real patient data — enforced technically (a seed that refuses a non-demo database, a required runtime flag), not just by policy.
This page reflects our current build status and will be updated as certification and audit milestones complete. If you need current, verifiable specifics for a procurement or compliance review, reach out directly.