Security & Trust

Built HIPAA-first, with a public roadmap you can hold us to

Your clients trust you with their health information, and you trust us with your practice. We maintain rigorous administrative, physical, and technical safeguards to support your compliance with federal privacy and security requirements — and we publish where we are headed next.

Live compliance & security standards

Everything in this section is true in the platform today — on every plan, for every practice.

Protecting the data itself

Encryption at rest

All Protected Health Information, attachments, and database backups are encrypted with AES-256.

Encryption in transit

Every session and data transfer is protected with modern TLS (1.2+, with TLS 1.3 where supported). PHI-bearing email is delivered through HIPAA-compliant infrastructure, and SMS reminders are minimal-content by design.

Role-based access control

Practitioners, front-desk staff, and billers see only the data their role requires, with granular clinical and financial permissions. Support-only roles never touch clinical records they do not need.

Tenant isolation at the database layer

Every practice’s data is isolated with row-level security enforced by the database itself — multi-tenant separation is a property of the data layer, not just the application.

Append-only audit logging

Access to PHI — views, edits, creations, exports, deletions — is captured in append-only audit logs with user identity and timestamps. Logs cannot be silently altered, supporting complete audit readiness for your practice.

Session protection

Automatic idle timeouts and stale-session checks protect both the practice portal and the client portal on shared and family devices.

Two-factor authentication

Every account can enable app-based two-factor authentication (TOTP), and active sessions are listed so a practice owner can see and revoke access from a device they no longer use.

How we operate

Business Associate Agreements

We execute a BAA with every practice on every plan — HIPAA coverage is included, never sold as an add-on. Our own subprocessors that touch PHI (hosting, email, SMS) operate under BAAs with us, so your vendor chain is covered end to end.

Your data stays yours

Export your entire practice — clients, notes, documents, invoices — at any time, in open formats, without asking us. A single client’s complete record can be exported on its own to satisfy a patient access request.

Breach notification

We maintain a documented incident response and breach notification procedure, and will notify an affected practice without unreasonable delay so you can meet your own obligations under the Breach Notification Rule.

Retention and deletion

A documented data retention schedule governs how long records are kept, and what happens to them if you leave. Clinical records outlive a subscription for a reason — you decide when they go, not us.

Your compliance, supported

Each practice is a Covered Entity in its own right. Alongside the BAA, we provide documentation to support your own program — including our HIPAA & Security Overview one-pager for your IT consultant or compliance reviewer.

The program behind it

Risk analysis

A documented risk assessment covering where PHI lives, what could reach it, and what we do about each finding. It is the control OCR cites more often than any other in enforcement actions, and the one most commonly missing — so it is stated first here rather than assumed.

Written policies

A documented policy set covering risk assessment, breach notification, contingency, retention and access control. Available to a practice or its reviewer on request, so an evaluation does not depend on taking a web page at its word.

Vendor due diligence

No subprocessor touches PHI before its BAA is signed and recorded. The current list is published on this page rather than supplied only when asked, and practices under BAA are notified when it changes — a subprocessor added quietly is the thing a compliance review is designed to catch.

Contingency planning

Documented contingency procedures covering backup, restoration and continued access to records during a disruption. Clinical records are the thing a practice cannot recreate, so this is treated as an availability requirement rather than an IT preference.

Formal program documentation, underway

The program is being documented formally against the NIST Cybersecurity Framework. That work is in progress today rather than finished, and it is described that way here for the same reason no certification dates are published below: an honest status is worth more to a reviewer than an optimistic one.

Our compliance & certification roadmap

Security is a continuous investment, not a checkbox. To support growing clinics, enterprise partners, and health systems, we maintain a clear path toward independent third-party attestation — and we would rather publish the roadmap than claim badges we have not yet earned.

Today — live

HIPAA Security & Privacy Rule safeguards

The administrative, physical, and technical safeguards above are live in the platform now, with BAAs executed for every practice and a security program aligned to the NIST Cybersecurity Framework.

Underway

International privacy readiness

We are building toward GDPR readiness for practices in the EU and UK, and toward the Canadian provincial health privacy requirements that govern clinicians there. Practices outside the United States should talk to us before signing up so we can confirm what we are able to support today.

Next

SOC 2 Type I

Independent attestation that our security controls are suitably designed — the first third-party checkpoint on the roadmap.

Then

SOC 2 Type II

The deeper attestation: controls tested for operating effectiveness over an extended observation period, not just a point in time.

Horizon

HITRUST

The healthcare industry’s most rigorous certification, supporting enterprise health systems and larger clinic groups. Our control framework is also mapped toward ISO 27001 alignment on the longer horizon.

Who else touches your data

We use a small number of specialist providers to run the platform. Every one that can touch Protected Health Information operates under a Business Associate Agreement with us. We will send the current named list on request.

FunctionWhat they handle
Hosting and databaseApplication hosting and the encrypted database holding practice and client records. United States regions.
Email deliveryTransactional and PHI-bearing email, delivered through HIPAA-compliant infrastructure.
SMS deliveryAppointment reminders. Minimal-content by design — no clinical detail in a text message.
Telehealth videoEncrypted video sessions. Calls are not recorded by the platform.
PaymentsCard processing and payouts. Card numbers never reach our servers.
Shipping and fulfilmentLabel generation and carrier rates for physical items sent to a client. Name and address only — no clinical information.
AnalyticsAnonymous, cookieless visitor counts on the public marketing site only. The practice app and client portal carry no third-party analytics at all.

Reporting a vulnerability

Report to security@myosimplified.com with details before disclosing. Stop and tell us at any client or health data. We acknowledge within two business days. We will not pursue legal action over good-faith research.

Have a security questionnaire or a specific control question?

We answer those directly — no gatekeeping, no sales detour. Download the HIPAA & Security Overview one-pager for your IT consultant, or write to us.

Get the HIPAA one-pagersecurity@myosimplified.com