The platforms we build house protected health information, clinical documentation, and billing data. We apply enterprise-grade, HIPAA-aligned security practices to every deployment.
Infrastructure Security
We deploy on established cloud infrastructure providers that maintain SOC 2 Type II and HITRUST-aligned compliance, with signed Business Associate Agreements in place. All data at rest is encrypted with AES-256, and all data in transit is protected with TLS 1.3.
Application Security
- Authentication: Hardened session management with support for multi-factor authentication on clinician and admin accounts.
- Access control: Role-based permissions ensure a clinician, biller, or administrator can only view records their role is authorized to access.
- Minimum necessary access: Client records are scoped to the care team directly involved in that client's treatment.
- Audit logging: All access to protected health information is logged and available for compliance review.
Payment Security
Emotional Well-Being does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.
Vulnerability Reporting
If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@emotionalwellbeing.us. We respond to all reports within 48 hours.