HIPAA & security

Built HIPAA-compliant from day one

Compliance is the wall that kept this app from existing. Not the design. Not the code. The compliance. It's why patients can't build their own tools, and why small developers stay out of health entirely.

Here's the honest version. Building software that touches health information means encryption at rest and in transit, access controls, audit logging, breach procedures, business associate agreements, signed infrastructure, and the kind of fine that ends a small company on a first offense. That risk is a wall, and for years the only people who could afford to stand on the other side of it were the giants — which is exactly why the tools patients actually need never got built.

We went at that wall first. Joshua runs hipaasoft.com, a HIPAA-compliant development company, and wrote a HIPAA training course for other developers — because we'd rather more small teams got in here than fewer. Organized.health runs on that same compliant foundation: a HIPAA-compliant server and database, encrypted storage, and an append-only audit trail of every access to your record.

We won't pretend security is ever finished. It's maintenance, forever. But you should know what's happening with your own information — so here's what we do.

Encrypted at rest and in transit

Managed keys on a HIPAA-compliant database, with the most sensitive identifiers encrypted a second time at the application layer.

An audit trail on every access

Append-only, retained for years, recording who touched what and when — ids and events, never the contents.

You control the access you grant

Caregivers, nurses and advocates get the role you give them, enforced on the server, revocable by you at any time.

Identity handled by a dedicated provider

We don't store your password. Sign-in, multi-factor and recovery live with a managed identity service built for it.

AI that stays inside the walls

Record organizing runs in our own HIPAA-compliant environment. Your chart is not training data for anybody.

Your records are yours to take

Export the whole thing as PDFs whenever you want. Leaving should be as easy as joining.

Your rights, and what to do if they're ignored

HIPAA is usually discussed as an obligation on providers. It's also a set of rights for you: to get a copy of your records, to ask for corrections when they're wrong, and to complain when a provider mishandles your information. Most people are never told they have them.