Skip to content

Security & Compliance

Built on a Foundation of Security, Privacy, and Trust

Post Acute Analytics handles sensitive clinical and operational data on behalf of health plans, health systems, and post-acute care providers. We hold ourselves to the highest standards of security and compliance, because our customers depend on it.

Certifications

Independently Verified Security and Compliance

SOC 2 Type II

Independently audited by Barr Advisory, our SOC 2 Type II report covers the Security, Availability, and Confidentiality trust service criteria. Available to customers and prospects under NDA.

HIPAA Compliant

We operate as a HIPAA-compliant Business Associate and execute Business Associate Agreements (BAAs) with all customers who process protected health information through our platform.

Annual Penetration Testing

We conduct annual third-party penetration testing of our platform. Findings are triaged, prioritized, and remediated in accordance with our internal vulnerability management policy.

Security Practices

How We Protect Your Data

Security is built into every layer of our platform and operations.

Encryption

All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256. Protected health information is never stored unencrypted.

Access Controls

Role-based access control (RBAC) is enforced across all systems. Privileged access is managed, logged, and reviewed on a regular basis.

Infrastructure Security

Our platform runs on AWS in U.S. regions only. We use network segmentation, security groups, and continuous cloud security monitoring to protect our environment.

Vulnerability Management

Continuous automated scanning of our codebase and infrastructure. Critical findings are remediated within 24 hours; high findings within 7 days.

Incident Response

A tested incident response plan governs how we detect, contain, and communicate security incidents. Customers are notified without undue delay in the event of a breach affecting their data.

Employee Security

All employees complete security and HIPAA awareness training upon hire and annually. Background checks are conducted for all staff with access to production systems.

Standards

Standards We Support

Built to interoperate securely across the healthcare ecosystem.

SMART on FHIR®

Secure, standards-based clinical data exchange

HL7®

Interoperability across EMR and care management systems

AES-256 Encryption

Industry-standard encryption for data at rest

TLS 1.2+

Encrypted data in transit across all connections

Responsible Disclosure

We take vulnerability reports seriously. If you believe you have identified a security issue in our platform or website, please contact us directly. We commit to acknowledging reports within 2 business days and working with you to investigate and resolve confirmed issues promptly.

Please do not publicly disclose findings before we have had the opportunity to investigate and respond.

Questions About Security or Compliance?

Our team is happy to discuss our security program, share our SOC 2 Type II report under NDA, or work through BAA requirements for your organization.