HIPAA requires a written Business Associate Agreement with each service provider that handles PHI on our behalf. We maintain an internal register of those providers, including our database, identity, hosting, email, cache, and observability providers, and the status of each agreement.
Data is encrypted in transit and at rest. Patient records are isolated at the application layer: every request is gated on the caller's role and on a verified relationship to that patient, and every read of a record is written to the audit log.