Security, Compliance & HIPAA

PatientIQ is engineered with advanced security controls to keep patient health information protected.

Encryption at Rest & In Transit

All Protected Health Information (PHI) is encrypted using industry-standard AES-256 at rest. Transport Layer Security (TLS 1.3) protects files and messages in transit.

Continuous Audit Trail Logging

Every clinical record request, profile update, or authentication event triggers an audit log. Logs track user ID, action timestamp, and client IP mappings to verify access compliance.

Role-Based Access Control (RBAC)

Strict software boundaries prevent cross-role traversal. Patients cannot access clinician note consoles, and clinics can only query authorized patient charts.

Business Associate Agreements (BAA)

PatientIQ enters into Business Associate Agreements (BAA) with medical providers and hosting companies to satisfy federal HIPAA liability directives.

Infrastructure Hardening

Our servers run inside isolated Virtual Private Clouds (VPC) with strict firewall boundaries. Automatic daily database backups are stored in geo-redundant storage with retention policies to prevent diagnostic record loss.