AccessPro HealthCare is built on HIPAA-compliant infrastructure with end-to-end encryption, audit logging, and enterprise-grade security at every layer.
All data is stored on AWS HIPAA-eligible services including RDS, S3, CloudFront, and SES. Our AWS Business Associate Agreement (BAA) covers all services handling Protected Health Information.
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption. Patient data never travels unencrypted between any system component.
Role-based access control ensures each user only sees data they are authorized to access. Agency isolation is enforced at the database level using Row Level Security.
Every access, modification, and deletion of Protected Health Information is logged with timestamp, user identity, and action taken. Logs are retained for 6 years per HIPAA requirements.
Secure JSON Web Tokens with automatic expiration protect every API request. Sessions expire automatically after 8 hours requiring re-authentication.
AWS CloudFront delivers the platform through secure HTTPS connections with SSL certificates. All communication is encrypted and verified.
| Protection Layer | Technology | Standard | Status |
|---|---|---|---|
| Data in Transit | TLS 1.2+ / HTTPS | NIST SP 800-52 | Active |
| Data at Rest | AES-256 Encryption | FIPS 140-2 | Active |
| Database Security | AWS RDS PostgreSQL + SSL | HIPAA Eligible | Active |
| File Storage | AWS S3 + CloudFront | HIPAA Eligible | Active |
| Authentication | JWT + bcrypt hashing | OAuth 2.0 | Active |
| Access Control | Row Level Security | HIPAA Required | Active |
| Audit Logging | PostgreSQL audit_log table | HIPAA Required | Active |
| Email Communications | AWS SES | HIPAA Eligible | Active |
| SMS Notifications | Twilio | HIPAA Compliant | Active |
| Intrusion Detection | AWS CloudWatch | NIST SP 800-94 | Active |
A Business Associate Agreement (BAA) is a legally required contract under HIPAA between a Covered Entity (your agency) and a Business Associate (AccessPro HealthCare) that handles Protected Health Information on your behalf.
Our BAA covers all data processing, storage, transmission, and destruction of PHI on our platform.
Ready to go live? Contact us to receive your signed BAA before your agency begins using AccessPro HealthCare with real patient data.
✉ Request BAA via Email Get Started TodayWe use AWS CloudWatch monitoring and audit logging to detect any unauthorized access or data breach immediately upon occurrence.
Covered Entities are notified within 60 days of breach discovery. If 500 or more individuals are affected, HHS and media are notified as required by law.
All breach notifications and remediation actions are documented and retained for 6 years per HIPAA requirements.