Your clients trust you with their health information, and you trust us with your practice. We maintain rigorous administrative, physical, and technical safeguards to support your compliance with federal privacy and security requirements — and we publish where we are headed next.
Everything in this section is true in the platform today — on every plan, for every practice.
All Protected Health Information, attachments, and database backups are encrypted with AES-256.
Every session and data transfer is protected with modern TLS (1.2+, with TLS 1.3 where supported). PHI-bearing email is delivered through HIPAA-compliant infrastructure, and SMS reminders are minimal-content by design.
Practitioners, front-desk staff, and billers see only the data their role requires, with granular clinical and financial permissions. Support-only roles never touch clinical records they do not need.
Every practice’s data is isolated with row-level security enforced by the database itself — multi-tenant separation is a property of the data layer, not just the application.
Access to PHI — views, edits, creations, exports, deletions — is captured in append-only audit logs with user identity and timestamps. Logs cannot be silently altered, supporting complete audit readiness for your practice.
Automatic idle timeouts and stale-session checks protect both the practice portal and the client portal on shared and family devices.
Every account can enable app-based two-factor authentication (TOTP), and active sessions are listed so a practice owner can see and revoke access from a device they no longer use.
We execute a BAA with every practice on every plan — HIPAA coverage is included, never sold as an add-on. Our own subprocessors that touch PHI (hosting, email, SMS) operate under BAAs with us, so your vendor chain is covered end to end.
Export your entire practice — clients, notes, documents, invoices — at any time, in open formats, without asking us. A single client’s complete record can be exported on its own to satisfy a patient access request.
We maintain a documented incident response and breach notification procedure, and will notify an affected practice without unreasonable delay so you can meet your own obligations under the Breach Notification Rule.
A documented data retention schedule governs how long records are kept, and what happens to them if you leave. Clinical records outlive a subscription for a reason — you decide when they go, not us.
Each practice is a Covered Entity in its own right. Alongside the BAA, we provide documentation to support your own program — including our HIPAA & Security Overview one-pager for your IT consultant or compliance reviewer.
A documented risk assessment covering where PHI lives, what could reach it, and what we do about each finding. It is the control OCR cites more often than any other in enforcement actions, and the one most commonly missing — so it is stated first here rather than assumed.
A documented policy set covering risk assessment, breach notification, contingency, retention and access control. Available to a practice or its reviewer on request, so an evaluation does not depend on taking a web page at its word.
No subprocessor touches PHI before its BAA is signed and recorded. The current list is published on this page rather than supplied only when asked, and practices under BAA are notified when it changes — a subprocessor added quietly is the thing a compliance review is designed to catch.
Documented contingency procedures covering backup, restoration and continued access to records during a disruption. Clinical records are the thing a practice cannot recreate, so this is treated as an availability requirement rather than an IT preference.
The program is being documented formally against the NIST Cybersecurity Framework. That work is in progress today rather than finished, and it is described that way here for the same reason no certification dates are published below: an honest status is worth more to a reviewer than an optimistic one.
Security is a continuous investment, not a checkbox. To support growing clinics, enterprise partners, and health systems, we maintain a clear path toward independent third-party attestation — and we would rather publish the roadmap than claim badges we have not yet earned.
The administrative, physical, and technical safeguards above are live in the platform now, with BAAs executed for every practice and a security program aligned to the NIST Cybersecurity Framework.
We are building toward GDPR readiness for practices in the EU and UK, and toward the Canadian provincial health privacy requirements that govern clinicians there. Practices outside the United States should talk to us before signing up so we can confirm what we are able to support today.
Independent attestation that our security controls are suitably designed — the first third-party checkpoint on the roadmap.
The deeper attestation: controls tested for operating effectiveness over an extended observation period, not just a point in time.
The healthcare industry’s most rigorous certification, supporting enterprise health systems and larger clinic groups. Our control framework is also mapped toward ISO 27001 alignment on the longer horizon.
We use a small number of specialist providers to run the platform. Every one that can touch Protected Health Information operates under a Business Associate Agreement with us. We will send the current named list on request.
Report to security@myosimplified.com with details before disclosing. Stop and tell us at any client or health data. We acknowledge within two business days. We will not pursue legal action over good-faith research.
We answer those directly — no gatekeeping, no sales detour. Download the HIPAA & Security Overview one-pager for your IT consultant, or write to us.