HIPAA surfaceBAA includedLeast-privilege access

Patient-data security is a system boundary, not a badge.

The security review follows the data: where PHI enters, which systems receive it, who can access it, what gets logged, and what the practice needs before launch.

AgreementBAA before PHI
TransportTLS 1.3
StorageAES-256
AdministrationRole access + MFA

The control register.

Buyers should be able to name the control, how it applies, and the acceptance check.

01

Business Associate Agreement

BAA included for practices handling PHI

Execute before patient data enters the system

02

Encryption

AES-256 at rest and TLS 1.3 in transit

Confirm every PHI-bearing connection in scope

03

Access

Role-based permissions and administrative MFA

Map each staff role before launch

04

Auditability

Data-access and modification trails

Confirm the events the practice needs to review

Follow PHI through the product.

The implementation review decides which of these paths are enabled for the practice.

01

Website and intake

Patient submissions, consent, routing, and the destination system.

02

Calls and messages

Recordings, transcripts, text content, transfers, and staff access.

03

Chart and scribe

Encounter inputs, draft documentation, signatures, and record retention.

04

Portal and payments

Identity, secure access, statements, card workflows, and connected vendors.

Before the first patient journey.

Security readiness is part of launch acceptance.

Signed BAA where required

Named administrative owners

Approved role and access matrix

Synthetic end-to-end test

Connected-vendor inventory

Incident and support contacts

Security questions.

01

When is the BAA signed?

Before the practice sends protected health information through an enabled MedSiteAI workflow.

02

Does every integration carry PHI?

No. Each connection is scoped separately. The implementation plan identifies which routes carry PHI and which are operational only.

03

How should staff access be configured?

Start from job responsibilities, grant the minimum access needed, require administrative MFA, and review access when roles change.

04

What should a security review cover?

The BAA, data flow, authentication, access roles, retention and deletion expectations, audit needs, connected vendors, and the incident contact path.

Put the data flow in front of the security owner.

We will walk through the enabled workflows, BAA, access plan, and connected vendors.

Book a Call