Skip to main content
Pellmoor

Security & Privacy

Your chart is not a marketing asset.

Several large telehealth companies have been penalized for sending patient health information to advertising platforms through website trackers. That was not a technical accident — it was a business decision. We made the opposite one, and this page describes the controls that back it up.

No advertising or analytics trackers on clinical pages

There is no Meta pixel, no Google Ads conversion tag, and no session-replay tool anywhere on this site. A tracker on a page about your medical condition transmits the fact of your condition. We run none.

We do not sell or share your information

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use your health information to target you with anything.

Technical and administrative controls

ControlWhat we doAuthority
Encryption in transitTLS 1.2+ with modern cipher suites and HSTS preload. Plain HTTP is not served. Internal service-to-service traffic is also mutually authenticated and encrypted.45 CFR 164.312(e)
Encryption at restProtected health information is encrypted field-by-field with AES-256-GCM before it is written, in addition to volume-level encryption. A stolen database file or an over-broad query does not yield readable PHI.45 CFR 164.312(a)(2)(iv)
Key managementKeys are held in a hardware-backed key management service, never on application disks, with documented annual rotation and split-knowledge procedures for the master key.NIST SP 800-57
Authenticationscrypt password hashing with a memory-hard work factor. TOTP multi-factor authentication is mandatory for every workforce account and offered to every patient. Accounts lock after repeated failures.45 CFR 164.312(d)
Automatic logoffSessions expire after 15 minutes of inactivity and have a hard 12-hour ceiling. Sessions are revocable server-side; a stolen token alone is not sufficient to maintain access.45 CFR 164.312(a)(2)(iii)
Access controlRole-based permissions plus a relationship check: a clinician with no treatment relationship to you cannot open your chart, and the attempt is recorded as a denial.45 CFR 164.502(b), 164.514(d)
Audit controlsEvery access to PHI — including reads — is logged with actor, subject, action, and outcome. Entries are HMAC-chained to their predecessor, so deletion or modification breaks verification. Retained a minimum of six years.45 CFR 164.312(b), 164.316(b)(2)
IntegrityConsent documents and Good Faith Estimates are content-hashed at signature, so we can prove exactly what text a patient was shown.45 CFR 164.312(c)
Transmission securityClinical communication happens inside the portal. Unencrypted email and SMS are used only for non-clinical notifications, and only with your separate documented consent.45 CFR 164.312(e)(1)
Backup and recoveryEncrypted, geographically separated backups with documented and exercised restore procedures, a defined recovery point objective, and an emergency-mode operation plan.45 CFR 164.308(a)(7)
Vendor managementA live register of every vendor that could touch PHI, with executed Business Associate Agreements, risk tier, and review date. No vendor is connected before its BAA is signed.45 CFR 164.308(b), 164.502(e)
Vulnerability managementDependency scanning on every build, annual third-party penetration testing, and documented remediation timelines by severity.45 CFR 164.308(a)(1)(ii)(A)–(B)

Governance

Who is accountable

HIPAA requires a named Privacy Officer and a named Security Officer. Ours are identified below, and you can reach them directly — not through a support queue.

Privacy Officer

TBD — appoint before go-live

privacy@pellmoorhealth.com

Security Officer

TBD — appoint before go-live

security@pellmoorhealth.com

Incident response

If something goes wrong

  • Suspected incidents are triaged within one hour of detection, around the clock.
  • A four-factor risk assessment determines whether an impermissible use or disclosure is a reportable breach, and that analysis is documented either way.
  • Affected individuals are notified without unreasonable delay and no later than 60 days from discovery.
  • HHS is notified per the Breach Notification Rule, and state notification laws — including the New York SHIELD Act and the Illinois Personal Information Protection Act — are applied in parallel.
  • Breaches affecting 500 or more residents of a state trigger prominent media notice.

Responsible disclosure

Found a vulnerability? Email security@pellmoorhealth.com. We will acknowledge within two business days and will not pursue legal action against good-faith research that respects patient privacy and avoids service disruption.