Trust

We hold ourselves to the same standard we ship to you.

A HIPAA platform that's not itself HIPAA-compliant is the sort of irony we try to avoid. Here's exactly how we handle your data, your PHI, and your trust.

HIPAA
BAA available

Signed with every customer. Default posture: PHI flows through hms.

SOC 2
Type II

Audited annually by Johanson Group. Report available on request.

HITRUST
r2 certified

Validated to the same standard hospitals hold themselves to.

Residency
U.S. only

All production data stays in AWS us-east-1 + us-west-2.

Data handling

How your data moves.

Plain English. No weasel words.

In transit

TLS 1.3, HSTS preloaded.

Every connection is encrypted with modern cipher suites. HTTP is never accepted — the browser is told before you even ask.

At rest

AES-256, per-tenant keys.

Your data is encrypted at rest with a key only your tenant can unwrap. Even our engineers can't read your policies without your request.

In AI

Nothing leaves your tenant.

Policy chat runs in a zero-retention AWS Bedrock deployment. Your prompts are not logged, not fine-tuned on, not seen by humans.

In backups

Encrypted, 35 days, versioned.

Point-in-time restore to any second in the last 35 days. Backup keys are rotated quarterly and never leave AWS KMS.

Sub-processors

Who else touches your data.

Short list on purpose.

Sub-processor Purpose Data Location BAA
Amazon Web ServicesHosting, storage, AI inferenceAll tenant dataUS-East, US-West
StripeSubscription billingBilling only (no PHI)USN/A
PostmarkTransactional emailUser email addressesUS
LinearInternal ticketingSupport correspondence (scrubbed)USN/A
OktaEmployee SSOOur staff onlyUSN/A

We notify customers 30 days in advance of any sub-processor change. The full current list is always at hipaa.inc/subprocessors.

Internal practices

The same checklist we ship.

We run our own HIPAA program inside hms. Every control, every task, same product you use. When you audit us, you're auditing the tool.

  • Mandatory background checks for all staff
  • Annual HIPAA & security training, 100% completion
  • Principle of least privilege on every production system
  • Quarterly penetration tests (Bishop Fox, 2024–present)
  • 90-second incident response SLA, 24/7
  • All MacBooks on our own managed fleet
Status: All systems secure
Last incident: 127 days ago · resolved in 6 min
Uptime (trailing 90d)99.98%
Mean time to detect48 sec
Mean time to resolve4m 20s
Critical patches applied ≤24h100%
Staff completed training 202524 / 24
View full status page →
Responsible disclosure

Found something? Tell us.

We pay bounties up to $10,000 for critical vulnerabilities. No lawyers, no legal threats — just a thank-you, a fix, and a check.

security@hipaa.inc

PGP key and full policy at hipaa.inc/security. Typical triage response: under 8 hours.

Want our SOC 2 report?

Send us a signed NDA and we'll share it within one business day.