Built for the trust your patients place in you
Patient data is the most sensitive information your practice handles. We protect it with the same rigor as a hospital IT department — without the staffing burden.
Independently audited. Continuously verified.
Compliance isn't a checkbox we tick once. Every framework below is actively maintained and independently audited.
HIPAA Compliant
HIPAA
Full alignment with the HIPAA Privacy, Security, and Breach Notification Rules. Business Associate Agreement (BAA) signed with every customer.
SOC 2 Type II
SOC 2
Independently audited annually against the AICPA Trust Services Criteria for Security, Availability, and Confidentiality.
HITECH Act
HITECH
Compliant with the Health Information Technology for Economic and Clinical Health Act, including breach notification requirements.
21 CFR Part 11
21 CFR 11
Electronic records and signatures meet FDA requirements for closed-system controls, identity verification, and audit trails.
GDPR Aligned
GDPR
Data Processing Addendum (DPA) and Standard Contractual Clauses available for EU-based practices and international data flows.
PCI DSS
PCI
Card data handled exclusively by PCI-DSS Level 1 certified payment processors. Cardholder data never touches our servers.
Encrypted everywhere — always.
PHI is encrypted at every layer: at rest, in transit, in backups, and in flight between services. Keys are isolated per practice and rotated automatically.
AES-256 at rest
All patient data, files, and backups are encrypted at rest using AES-256, with keys managed by AWS KMS and rotated automatically.
TLS 1.3 in transit
Every connection between the browser, mobile app, and our servers is encrypted with TLS 1.3 and HSTS-pinned. Older protocols are disabled.
Per-tenant key isolation
Cryptographic isolation at the practice level. A compromised key for one tenant cannot expose data belonging to another.
Encrypted backups
Backups are encrypted, geo-redundant, and tested via quarterly restore drills. Retention periods are configurable per practice.
Least privilege, by default.
Every action is gated by role, every login is logged, and every export is auditable. Patients see their own data; clinicians see what their role and patient relationship require — nothing more.
Role-based access (RBAC)
Granular permissions per role — admin, provider, front desk, biller, patient. Permissions audited on every action.
Multi-factor authentication
MFA available for all users. Required for admin accounts, EPCS prescribers, and any account with access to bulk PHI export.
Complete audit logs
Every view, edit, login, and export is logged with user, timestamp, IP, and device. Logs are immutable and retained for 7 years.
SSO & SCIM
SAML 2.0 single sign-on and SCIM provisioning supported on Business and Enterprise plans. Works with Okta, Azure AD, Google Workspace.
Resilient by design.
Active-active deployments, automated failover, and a 99.9% uptime SLA — backed by continuous monitoring and tested recovery drills.
US-based, isolated infrastructure
Hosted in AWS us-east-1 and us-west-2 with no shared infrastructure with non-healthcare workloads. EU residency option available.
99.9% uptime SLA
Active-active, multi-AZ deployment with automated failover. Real-time status published at status.nexiumcare.com.
Continuous backups + DR
Point-in-time recovery to any moment in the past 35 days. Cross-region disaster recovery with a 1-hour RPO and 4-hour RTO.
24/7 monitoring
Security operations center monitors threat signals continuously. Anomaly detection on auth, exfil, and configuration events.
What we do, every day.
Our security team operates a continuous program, not a once-a-year audit cram.
- Annual third-party penetration testing with public summary on request
- Quarterly internal vulnerability scans across all services
- Static and dynamic application security testing (SAST/DAST) on every deployment
- Required code review and dependency scanning before production release
- Background checks and HIPAA training required for every employee with PHI access
- Documented incident response plan with 1-hour internal notification, 60-day breach notification per HIPAA
- Subprocessor list published and updated on every change
- Right-to-deletion and right-to-export available for every practice and patient
Documents & contacts
Everything your IT, legal, and compliance teams need.
Business Associate Agreement
Signed with every customer at no charge. Request a counter-signed copy.
Request BAAData Processing Addendum
For EU-based practices and any customer requesting GDPR-aligned processing terms.
Request DPASystem Status
Real-time uptime and incident history for every NexiumCare service.
View status pageHave a security question?
Our security team answers vendor questionnaires, reviews custom DPAs, and walks IT teams through our control set.
