Security
Encryption & Transport
Data in transit
TLS 1.3 encryption
Data at rest
AES-256 encryption
Passwords
Bcrypt hashed, never stored plaintext
JWT tokens
RSA-2048 signed, 1-hour expiry
Access Control
Authentication
Email + password required
Authorization
Role-based (Admin/Provider/Nurse/Billing/Patient)
Session timeout
8 hours inactivity
Audit logging
All access recorded
Infrastructure
Hosting
Microsoft Azure App Service
Region
US West (HIPAA eligible)
Backups
Daily, retained 30 days
Disaster recovery
RPO 4h, RTO 8h
Compliance
HIPAA
Full compliance, BAA in place
SOC 2
Azure SOC 2 Type II
Penetration testing
Annual third-party assessment
Incident response
<4 hour notification