Security & Privacy
Your chart is not a marketing asset.
Several large telehealth companies have been penalized for sending patient health information to advertising platforms through website trackers. That was not a technical accident — it was a business decision. We made the opposite one, and this page describes the controls that back it up.
No advertising or analytics trackers on clinical pages
There is no Meta pixel, no Google Ads conversion tag, and no session-replay tool anywhere on this site. A tracker on a page about your medical condition transmits the fact of your condition. We run none.
We do not sell or share your information
We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your health information to target you with anything.
Technical and administrative controls
| Control | What we do | Authority |
|---|---|---|
| Encryption in transit | TLS 1.2+ with modern cipher suites and HSTS preload. Plain HTTP is not served. Internal service-to-service traffic is also mutually authenticated and encrypted. | 45 CFR 164.312(e) |
| Encryption at rest | Protected health information is encrypted field-by-field with AES-256-GCM before it is written, in addition to volume-level encryption. A stolen database file or an over-broad query does not yield readable PHI. | 45 CFR 164.312(a)(2)(iv) |
| Key management | Keys are held in a hardware-backed key management service, never on application disks, with documented annual rotation and split-knowledge procedures for the master key. | NIST SP 800-57 |
| Authentication | scrypt password hashing with a memory-hard work factor. TOTP multi-factor authentication is mandatory for every workforce account and offered to every patient. Accounts lock after repeated failures. | 45 CFR 164.312(d) |
| Automatic logoff | Sessions expire after 15 minutes of inactivity and have a hard 12-hour ceiling. Sessions are revocable server-side; a stolen token alone is not sufficient to maintain access. | 45 CFR 164.312(a)(2)(iii) |
| Access control | Role-based permissions plus a relationship check: a clinician with no treatment relationship to you cannot open your chart, and the attempt is recorded as a denial. | 45 CFR 164.502(b), 164.514(d) |
| Audit controls | Every access to PHI — including reads — is logged with actor, subject, action, and outcome. Entries are HMAC-chained to their predecessor, so deletion or modification breaks verification. Retained a minimum of six years. | 45 CFR 164.312(b), 164.316(b)(2) |
| Integrity | Consent documents and Good Faith Estimates are content-hashed at signature, so we can prove exactly what text a patient was shown. | 45 CFR 164.312(c) |
| Transmission security | Clinical communication happens inside the portal. Unencrypted email and SMS are used only for non-clinical notifications, and only with your separate documented consent. | 45 CFR 164.312(e)(1) |
| Backup and recovery | Encrypted, geographically separated backups with documented and exercised restore procedures, a defined recovery point objective, and an emergency-mode operation plan. | 45 CFR 164.308(a)(7) |
| Vendor management | A live register of every vendor that could touch PHI, with executed Business Associate Agreements, risk tier, and review date. No vendor is connected before its BAA is signed. | 45 CFR 164.308(b), 164.502(e) |
| Vulnerability management | Dependency scanning on every build, annual third-party penetration testing, and documented remediation timelines by severity. | 45 CFR 164.308(a)(1)(ii)(A)–(B) |
Governance
Who is accountable
HIPAA requires a named Privacy Officer and a named Security Officer. Ours are identified below, and you can reach them directly — not through a support queue.
Privacy Officer
TBD — appoint before go-live
privacy@pellmoorhealth.com
Security Officer
TBD — appoint before go-live
security@pellmoorhealth.com
Incident response
If something goes wrong
- Suspected incidents are triaged within one hour of detection, around the clock.
- A four-factor risk assessment determines whether an impermissible use or disclosure is a reportable breach, and that analysis is documented either way.
- Affected individuals are notified without unreasonable delay and no later than 60 days from discovery.
- HHS is notified per the Breach Notification Rule, and state notification laws — including the New York SHIELD Act and the Illinois Personal Information Protection Act — are applied in parallel.
- Breaches affecting 500 or more residents of a state trigger prominent media notice.
Responsible disclosure
Found a vulnerability? Email security@pellmoorhealth.com. We will acknowledge within two business days and will not pursue legal action against good-faith research that respects patient privacy and avoids service disruption.