Security and privacy
Your medical records are the most sensitive documents you own
Your medical records stay in an isolated AWS GovCloud environment. Only authorized representatives can access your medical records. Each medical record is retained for 90 days from when it is first received, then deleted.
- AWS GovCloud
- FedRAMP-aligned
- Login.gov IAL2
- Section 508 and WCAG 2.1 AA
- SDVOSB
- PHI redaction and tokenizationPlanned
How it is built
How your records are protected
Your records stay in isolated GovCloud
Your medical records stay in an isolated AWS GovCloud environment. We do not download medical-record personally identifiable information (PII) to staff devices or copy it into public website systems.
Access for authorized representatives only
Access to your medical records is restricted to authorized representatives within the isolated GovCloud environment.
A 90-day data retention period
Each medical record is retained for 90 days from when it is first received, then deleted.
Versioned and traceable
Every analysis records the engine version, the policy version, and the versions of the signal and presumptive registries that produced it. Any result can be traced back to the exact rules in force when it was generated.
A source behind every finding
Findings cite the document they came from. A conclusion with nothing behind it is not something the system is built to produce.
The redaction layer
PlannedSeparating identity from clinical content
The planned redaction layer is designed to reduce exposure of personal identifiers during analysis. These requirements explain how it must handle original records, masked text, and identity access.
Separate identifiers before analysis
The layer is designed to replace personal identifiers before text reaches analysis and search indexes. Original records remain protected in the isolated record environment; application logs must not contain raw medical content or identifiers.
The clinical meaning survives
Within an authorized record review, consistent replacement labels let analysis connect related findings while preserving clinical meaning, including whether a symptom was denied or confirmed.
Resolution is privileged and audited
Restoring an identity must require an authenticated, authorized request inside the protected environment. Each access must be recorded in an audit trail without copying sensitive record content into the log.
Masked records still need protection
Replacing a name does not make a medical record anonymous. Masked clinical text remains sensitive and subject to the same access, isolation, and retention rules. Identifiable source records are restricted to authorized representatives.
Redaction and tokenization are planned safeguards. This section describes their design requirements and does not describe them as already protecting production records.
Compliance posture
Control mapping to HIPAA and FedRAMP requirements
The platform is architected and operated to FedRAMP Moderate baseline controls, with FedRAMP High alignment on the security-critical subsystems.
| Control | Mechanism |
|---|---|
| Encryption | AES-256 at rest via KMS; TLS 1.2+ in transit. |
| Network isolation | Private VPC subnets, no public path to the backend. |
| Access | Authorized representatives only, with least-privilege IAM roles. |
| Audit | CloudTrail plus append-only application audit logging. |
| Residency and retention | Isolated AWS GovCloud; deletion 90 days after each record is first received. |
| Evidence integrity | Signed artifacts with content-addressed hashing. |
Stated precisely
A control mapping is a mapping. We are FedRAMP-aligned and we support the authorization process; we do not claim an authorization we have not been granted.
Cryptographic packaging is FIPS-ready.
When a certification lands we will name the issuing body and the date on this page. Until then this is what we can put our name to.
If you evaluate vendors for a living, this paragraph is the one that tells you whether the rest of the page is trustworthy.
Veteran data
Our commitments to your privacy
- No veteran data is ever sold, rented, licensed or monetized.
- No advertising, no profiling, no cross-site tracking.
- Only data the veteran explicitly authorizes is retrieved.
- We do not download medical-record personally identifiable information (PII) to staff devices or copy it into public website systems.
- Your medical records stay in an isolated AWS GovCloud environment.
- Only authorized representatives can access your medical records.
- Each medical record is retained for 90 days from when it is first received, then deleted.
Measured performance
Measured against our reference corpus
We publish the measurement and the method rather than a headline number, because the method is what makes the number mean anything.
These are controlled corpus figures, not a real-world accuracy rate. Real-world accuracy requires labeled real documents and outcome comparison. We publish the measurement and the method, not a headline number we cannot defend.
Next step
Reviewing this for a deployment?
We can walk through the boundary, the redaction contract, the audit trail and the control mapping in detail.