Skip to main content

Security Posture Overview

Transparent, deterministic controls ensure every patient interaction is protected. Use this overview to navigate our HIPAA stance, encryption posture, access controls, and audit standards. Jump directly to HIPAA & BAA or Access Control & RLS for deeper reference.

Private Evidence

Need deeper evidence (RLS matrices, incident runbooks, SOC artifacts)? Request access to the private documentation bundle via Partner Ops.

Security FAQs

  • Do you sign a BAA? - Yes. We execute a BAA with partners and maintain BAAs with all subcontractors handling PHI.
  • Where is data stored? - In our Supabase project’s configured region with encrypted storage and backups.
  • How do you control access? - Azure Entra SSO for staff; RLS policies enforce tenant‑ and role‑level isolation in Postgres.
  • How long do you retain logs? - Audit logs are retained to meet payer and regulatory requirements; extended retention available by request.
  • How do you handle incidents? - We follow a documented IR playbook with defined SLAs and notification timelines; detailed evidence is available privately on request.

Compliance Checklist

Control AreaWhat to ReviewArtifacts
Privacy & ConsentPatient consent flow, opt-out handlingPartner Ops portal demo, consent schema
Data ResidencySupabase region, backup replicationSupabase config, Pulumi plan (coming)
Vendor AlignmentSub-BAAs and security questionnairesVendor evidence index (private)
Incident ResponseEscalation matrix and breach notification timelineIncident Response Playbooks (private)
Last updated October 1, 2025 by Profound Health.
© 2025 Profound Health Institute.HIPAA Compliant - BAA Available