Security & Compliance
Built on a Foundation of Security, Privacy, and Trust
Post Acute Analytics handles sensitive clinical and operational data on behalf of health plans, health systems, and post-acute care providers. We hold ourselves to the highest standards of security and compliance, because our customers depend on it.
Certifications
Independently Verified Security and Compliance
SOC 2 Type II
Independently audited by Barr Advisory, our SOC 2 Type II report covers the Security, Availability, and Confidentiality trust service criteria. Available to customers and prospects under NDA.
HIPAA Compliant
We operate as a HIPAA-compliant Business Associate and execute Business Associate Agreements (BAAs) with all customers who process protected health information through our platform.
Annual Penetration Testing
We conduct annual third-party penetration testing of our platform. Findings are triaged, prioritized, and remediated in accordance with our internal vulnerability management policy.
Security Practices
How We Protect Your Data
Security is built into every layer of our platform and operations.
Encryption
All data is encrypted in transit using TLS 1.2+ and encrypted at rest using AES-256. Protected health information is never stored unencrypted.
Access Controls
Role-based access control (RBAC) is enforced across all systems. Privileged access is managed, logged, and reviewed on a regular basis.
Infrastructure Security
Our platform runs on AWS in U.S. regions only. We use network segmentation, security groups, and continuous cloud security monitoring to protect our environment.
Vulnerability Management
Continuous automated scanning of our codebase and infrastructure. Critical findings are remediated within 24 hours; high findings within 7 days.
Incident Response
A tested incident response plan governs how we detect, contain, and communicate security incidents. Customers are notified without undue delay in the event of a breach affecting their data.
Employee Security
All employees complete security and HIPAA awareness training upon hire and annually. Background checks are conducted for all staff with access to production systems.
Standards
Standards We Support
Built to interoperate securely across the healthcare ecosystem.
SMART on FHIR®
Secure, standards-based clinical data exchange
HL7®
Interoperability across EMR and care management systems
AES-256 Encryption
Industry-standard encryption for data at rest
TLS 1.2+
Encrypted data in transit across all connections
Responsible Disclosure
We take vulnerability reports seriously. If you believe you have identified a security issue in our platform or website, please contact us directly. We commit to acknowledging reports within 2 business days and working with you to investigate and resolve confirmed issues promptly.
Please do not publicly disclose findings before we have had the opportunity to investigate and respond.
Questions About Security or Compliance?
Our team is happy to discuss our security program, share our SOC 2 Type II report under NDA, or work through BAA requirements for your organization.