Security
Encryption & Transport
Data in transit TLS 1.3 encryption
Data at rest AES-256 encryption
Passwords Bcrypt hashed, never stored plaintext
JWT tokens RSA-2048 signed, 1-hour expiry
Access Control
Authentication Email + password required
Authorization Role-based (Admin/Provider/Nurse/Billing/Patient)
Session timeout 8 hours inactivity
Audit logging All access recorded
Infrastructure
Hosting Microsoft Azure App Service
Region US West (HIPAA eligible)
Backups Daily, retained 30 days
Disaster recovery RPO 4h, RTO 8h
Compliance
HIPAA Full compliance, BAA in place
SOC 2 Azure SOC 2 Type II
Penetration testing Annual third-party assessment
Incident response <4 hour notification