Security & Compliance

Built for the trust your patients place in you

Patient data is the most sensitive information your practice handles. We protect it with the same rigor as a hospital IT department — without the staffing burden.

Certifications & Frameworks

Independently audited. Continuously verified.

Compliance isn't a checkbox we tick once. Every framework below is actively maintained and independently audited.

Active

HIPAA Compliant

HIPAA

Full alignment with the HIPAA Privacy, Security, and Breach Notification Rules. Business Associate Agreement (BAA) signed with every customer.

Audited Annually

SOC 2 Type II

SOC 2

Independently audited annually against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality.

Active

HITECH Act

HITECH

Compliant with the Health Information Technology for Economic and Clinical Health Act, including breach notification requirements.

Active

21 CFR Part 11

21 CFR 11

Electronic records and signatures meet FDA requirements for closed-system controls, identity verification, and audit trails.

DPA Available

GDPR Aligned

GDPR

Data Processing Addendum (DPA) and Standard Contractual Clauses available for EU-based practices and international data flows.

Outsourced — Level 1

PCI DSS

PCI

Card data handled exclusively by PCI-DSS Level 1 certified payment processors. Cardholder data never touches our servers.

Encryption

Encrypted everywhere — always.

PHI is encrypted at every layer: at rest, in transit, in backups, and in flight between services. Keys are isolated per practice and rotated automatically.

AES-256 at rest

All patient data, files, and backups are encrypted at rest using AES-256, with keys managed by AWS KMS and rotated automatically.

TLS 1.3 in transit

Every connection between the browser, mobile app, and our servers is encrypted with TLS 1.3 and HSTS-pinned. Older protocols are disabled.

Per-tenant key isolation

Cryptographic isolation at the practice level. A compromised key for one tenant cannot expose data belonging to another.

Encrypted backups

Backups are encrypted, geo-redundant, and tested via quarterly restore drills. Retention periods are configurable per practice.

Access Controls

Least privilege, by default.

Every action is gated by role, every login is logged, and every export is auditable. Patients see their own data; clinicians see what their role and patient relationship require — nothing more.

Role-based access (RBAC)

Granular permissions per role — admin, provider, front desk, biller, patient. Permissions audited on every action.

Multi-factor authentication

MFA available for all users. Required for admin accounts, EPCS prescribers, and any account with access to bulk PHI export.

Complete audit logs

Every view, edit, login, and export is logged with user, timestamp, IP, and device. Logs are immutable and retained for 7 years.

SSO & SCIM

SAML 2.0 single sign-on and SCIM provisioning supported on Business and Enterprise plans. Works with Okta, Azure AD, Google Workspace.

Infrastructure

Resilient by design.

Active-active deployments, automated failover, and a 99.9% uptime SLA — backed by continuous monitoring and tested recovery drills.

US-based, isolated infrastructure

Hosted in AWS us-east-1 and us-west-2 with no shared infrastructure with non-healthcare workloads. EU residency option available.

99.9% uptime SLA

Active-active, multi-AZ deployment with automated failover. Real-time status published at status.nexiumcare.com.

Continuous backups + DR

Point-in-time recovery to any moment in the past 35 days. Cross-region disaster recovery with a 1-hour RPO and 4-hour RTO.

24/7 monitoring

Security operations center monitors threat signals continuously. Anomaly detection on auth, exfil, and configuration events.

Security Program

What we do, every day.

Our security team operates a continuous program, not a once-a-year audit cram.

  • Annual third-party penetration testing with public summary on request
  • Quarterly internal vulnerability scans across all services
  • Static and dynamic application security testing (SAST/DAST) on every deployment
  • Required code review and dependency scanning before production release
  • Background checks and HIPAA training required for every employee with PHI access
  • Documented incident response plan with 1-hour internal notification, 60-day breach notification per HIPAA
  • Subprocessor list published and updated on every change
  • Right-to-deletion and right-to-export available for every practice and patient

Have a security question?

Our security team answers vendor questionnaires, reviews custom DPAs, and walks IT teams through our control set.