Your Data Security Is Our Priority
We implement industry-leading security practices designed to protect sensitive medical equipment data and maintain compliance readiness.
HIPAA-Aware Design
Our platform is designed with HIPAA awareness in mind. We do not require Protected Health Information (PHI) for any repair service. Clear warnings are displayed throughout the submission process to prevent accidental PHI uploads. If any PHI is inadvertently included, our secure handling policies ensure proper containment and notification.
Encryption
All data encrypted in transit (TLS 1.3) and at rest using AES-256. No exceptions.
Role-Based Access
Strict RBAC with Admin, Technician, Billing, and Customer roles. Least-privilege enforced.
Authentication
Strong password policies with optional MFA. Session timeouts and automatic logouts on inactivity.
Audit Logging
Complete access and change logs for every record. Downloadable activity reports for compliance.
Secure Infrastructure
IP/rate limiting, DDoS protection, and secure file uploads with expiring access links.
Data Minimization
Only minimum necessary information is collected. PHI is never required—warnings prevent accidental uploads.
Compliance Ready
Change history per ticket, consent checkboxes, terms acceptance, and data retention policies.
Session Security
Automatic session timeouts, secure cookie handling, and forced re-authentication for sensitive actions.
Data Retention
Configurable retention periods. Automated purging of expired records with audit trail.
Network Security
Rate limiting, IP allowlisting options, and anomaly detection for suspicious access patterns.
Incident Response
Documented incident response procedures with notification protocols and remediation workflows.
Backup & Recovery
Regular encrypted backups with tested disaster recovery procedures and defined RPO/RTO.