Built for healthcare from day one

Six controls and practices relevant to a healthcare security review.

  • Tenant isolation enforced at the database, not the application. Tenant-boundary behavior is tested in the release suite, with current evidence available during diligence.
  • Patient data minimized everywhere it is not needed. Operational and support views are metadata-first; opening protected information requires a stated purpose and a time-limited session, and it is audited.
  • Patient-facing notifications minimize sensitive content. Text messages carry no patient name, no medication and no practice name.
  • Every access and change is audited. Who, what, when, and to which record.
  • Multi-factor authentication is required for clinical workforce roles. There is an identity-verified, audited recovery path, and break-glass emergency access that the account owner reviews after the fact.
  • Accessibility checks are part of release work. The marketing site is checked for keyboard use, reduced motion, semantic markup, color contrast, and common automated violations.

Examples of automated release checks

Automated checks run as part of the release process. Current evidence and scope are available during diligence.

Automated verification that gates an AlgoMeds release.
What is checkedHow
Security boundaries and tenant isolationAutomated authorization and tenant-boundary tests run in the release suite; current evidence is available during diligence.
Authorization, adversarially and across a lifecycleAdversarial and lifecycle authorization testing runs inside the same gate, not as an annual exercise.
Form autofill and refill coverageAutomated checks cover expected values across active templates.
Signature placementSignature targets are checked programmatically for a valid page and signing area.
AccessibilityRepresentative marketing-site routes are checked for keyboard use, semantic markup, reduced motion and color contrast.

How it is deployed

  • Browser-based. Nothing to install on practice machines, and no IT project to go live.
  • Hosted on managed cloud infrastructure under standard healthcare agreements, with encrypted storage and documented backup and restore procedures.
  • Data-flow and boundary documentation is available for security review.

Security review and diligence

We are questionnaire-ready. We maintain a customer security FAQ, a data-flow and boundary document, and an evidence checklist for buyer diligence. Those are released under NDA rather than published, which is also why this page does not describe authentication mechanisms, token designs, isolation implementation or infrastructure topology.

What we will not claim

We describe our architecture as HIPAA-aligned and we make a BAA available. We do not upgrade that into certification language our current attestations do not support, and we do not name our infrastructure, messaging or fax vendors in public copy. Detailed answers and current evidence are available through the diligence process.

Security questions practices ask

Will AlgoMeds sign a BAA?

Yes. A business associate agreement is available. AlgoMeds is built on a HIPAA-aligned architecture, and the BAA is part of standard onboarding rather than an escalation.

How is one practice’s data kept separate from another’s?

Tenant boundaries are enforced at the database layer and tested in the release suite. We provide current architecture and test evidence during security review.

What can AlgoMeds staff see?

Operational and support views are metadata-first. Opening protected information requires a stated purpose and a time-limited session, and every such access is audited.

What is in the text messages you send to patients?

Patient-facing notification templates are designed to omit patient names, medication names, practice names, and clinical detail. Request the current control evidence during security review.

Do you require multi-factor authentication?

Multi-factor authentication is required for clinical workforce roles, with an identity-verified, audited recovery path. Break-glass emergency access exists and is reviewed after the fact by the account owner.

Are you SOC 2 certified?

We publish what our current attestations support and nothing beyond it. For the current status, the customer security FAQ, the data-flow and boundary document and the evidence checklist, ask us directly. Those are released under NDA as part of security review.

Is the product accessible?

The marketing site includes keyboard, reduced-motion, semantic-markup, and automated accessibility checks. Ask for current product accessibility results during diligence.

What happens to our data if we leave?

Practices can export their data. Ask us for the current data export and retention terms in writing during diligence rather than relying on a marketing page.

Send us your security questionnaire.

We keep a customer security FAQ, a data-flow and boundary document and an evidence checklist ready for diligence.