We align with HIPAA and SOC 2 principles across people, process, and technology. Encryption in transit and at rest, role-based access, immutable audit logs, and rigorous change control help protect PHI while keeping your practice productive.
Practical, enforced controls mapped to HIPAA and SOC 2 principles.
TLS 1.2+ for data in transit and AES-256 at rest across databases, snapshots, and object storage.
Least-privilege IAM, MFA, IP restrictions for admin, fine-grained RBAC in app and infra.
Immutable, signed audit logs with tamper-evident hashing and retention to meet record-keeping needs.
Automated encrypted backups, PITR, tested restore runbooks, and regional redundancy.
Protected branches, code review, CI security checks, controlled deploys with audit trails.
Review of sub-processors, data flow diagrams, and BAAs where required.
We maintain policies mapped to HIPAA requirements and SOC 2 principles, including access control, change control, business continuity, and incident response.
MediChatApp is designed for Greenway Intergy environments. We follow the principle of minimum necessary when processing PHI for communications, check-in, portal, and revenue automation modules.
Patient demographics, appointments, messaging content, and optional encounter/charge metadata.
Encrypted databases and object storage; strict retention with purge workflows.
TLS-only, signed requests; IP allowlists for admin endpoints.
RBAC, MFA, granular logs of access events with export capability.
Answers to common security and compliance questions.
Yes. We offer a Business Associate Agreement and review sub-processor BAAs as part of onboarding.
Encryption in transit and at rest, strict RBAC, immutable audit logging, and monitored infrastructure with backup/DR.
Yes. Our integrations and workflows are built for Greenway Intergy environments with opt-in automations.
We can share HIPAA and SOC 2 principle mappings, plus policy excerpts, under NDA.