Skip to content

Trust center · Security & HIPAA

Security that earns trust.

Clinician and patient trust is the highest priority at palmER. All data follows HIPAA-compliant storage and processing protocols: established compliance standards combined with modern cloud security.

HIPAA CompliantHIPAA Compliant
0
Incidents or breaches · since 2011
AES-256
Encryption · data at rest
TLS 1.2+
Encryption · data in transit
Architecture
HIPAA-first by design
Built with HIPAA compliance at the core: advanced encryption, strict access controls, continuous monitoring, and adherence to best practices.
Data handling
Encrypted, everywhere
All data is encrypted at rest and in transit. Multiple layers of access controls prevent unauthorized access to our systems and data.
Monitoring
Watched around the clock
Real-time threat monitoring and automated anomaly detection run 24/7 to identify and address potential security threats.

Administrative · Technical · Physical

Comprehensive safeguards, across every layer.

palmER implements administrative, technical, and physical security controls to keep your data secure and maintain HIPAA compliance.

Administrative
  • Background checks and annual security training for all staff
  • Regular HIPAA risk assessments
  • Vendors sign Business Associate Agreements
Technical
  • Role-based access controls
  • Complete audit trail of all activity
  • Network segmentation isolates backend systems
  • Vulnerability assessments and penetration testing
Physical & infrastructure
  • US data centers with active redundancy
  • Identity management and network controls
  • Firewall inspection of all traffic
  • Redundant systems for high availability
Data lifecycle
Protected at every stage.
Collection & processing

Automatic PHI detection ensures data only flows where you intend. Zero-retention agreements with AI providers: PHI is never retained or used for training.

Storage & retention

Encrypted at rest and in transmission. Audio is never saved, patient data auto-deletes within 24 hours, and deleted data is securely and permanently removed. There is no shadow record of your encounters: nothing exists to be requested later beyond the note you signed.

Access & auditing

Users only access what their work requires. Audit logs track all system activity.

Backup & recovery

Continuous automated backups, regularly tested for fast restoration.

Secure development
Security, built in.
Cybersecurity is integrated into our development lifecycle, so security is part of every aspect of the platform.
  • Secure coding standards and code reviews before any deploy
  • SAST/DAST testing at multiple stages of development
  • Automated scans of codebase and infrastructure
  • Security gates at every stage of the DevOps pipeline

Business Associate Agreements

The BAA is built into our terms of service: compliance without any additional steps from you.

Security standards

AES-256 at rest, TLS 1.2+ in transit, and security best practices across all infrastructure.

Data sovereignty

Stored and processed exclusively in HIPAA-compliant US data centers. Never sold, shared, or repurposed.

Questions · Security desk

Questions about security? We’re happy to answer.

We’re happy to answer any questions about how palmER protects your data and ensures HIPAA compliance. Reach out to learn more.