HIPAA Compliance & Security
Solution Compass is built from the ground up with healthcare-grade security controls to protect sensitive organizational and patient data.
Your compliance team can check our work
All AI runs on hardware you control
No OpenAI, no Anthropic, no third-party AI provider. There are no credentials for one anywhere in the environment, which is a stronger statement than a policy — there is nothing configured that could send your content to one by mistake.
Two subprocessors
Resend for transactional email, Cloudflare for DNS and WAF. A third, Microsoft Graph, only if you switch SharePoint sync on — your tenant, your consent, and you can leave it off.
We publish the answers that are “no”
No SOC 2. No HITRUST. No clinical decision support. You will find that out in week six of an evaluation anyway, so you may as well read it here in week one.
HIPAA Compliance Overview
Solution Compass is designed to meet the requirements of the Health Insurance Portability and Accountability Act (HIPAA). Our platform implements administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI).
Business Associate Agreement (BAA)
We offer Business Associate Agreements (BAAs) to all covered entities and their business associates. A signed BAA is required before any ePHI is processed on the platform. Contact us to initiate the BAA process.
Encryption & Data Protection
- AES-256 encryption at rest for all stored documents, per organization
- TLS 1.2+ encryption for all data in transit
- Organization-specific encryption keys with no cross-tenant key sharing
- Private storage buckets with path-based access control
Access Controls (RBAC)
- Role-Based Access Control: Super Admin, Org Admin, Contributor
- Row-Level Security (RLS) enforced at the database level on every table
- Complete tenant isolation — users only see data from their organization
- Server-side role verification on all privileged operations
- Session timeout controls configurable per organization
Zero-Retention & PHI Redaction
- PII/PHI redaction filters on all external API responses (SSN, credit cards, emails, phone numbers)
- AI responses filter personal identifiers while retaining procedural knowledge
- No cross-tenant AI model training — organizational data is strictly isolated
- Configurable data retention policies per organization
Audit Trails & Logging
- Comprehensive audit log of all user actions (logins, data access, role changes, exports)
- Document access logging with user ID, filename, org ID, and timestamps
- Chat question logging for quality assurance and compliance reporting
- Immutable audit records — logs cannot be modified or deleted by users
- Super admin access to platform-wide audit history
Infrastructure Security
- Single-tenant, dedicated infrastructure — your data is not co-mingled in a shared multi-tenant cloud
- AI inference runs entirely on our own hardware. No prompt, document, or answer is ever sent to a third-party model provider such as OpenAI or Anthropic, so none of your content can be retained for model training
- US-based hosting; no offshore data processing
- DDoS protection and TLS termination at the network edge
- IP-based rate limiting on public-facing endpoints (5 requests / 15 minutes)
- HTTPS enforcement with strict security headers and a server-enforced Content Security Policy
- Security patching performed directly by the platform operator on a defined cadence, not deferred to a third-party host
Authentication & Identity
- Email verification required before platform access
- Configurable password complexity requirements
- Leaked password protection (HaveIBeenPwned integration)
- Secure session management with configurable timeouts
- No anonymous sign-ups — all users must be invited or register with verified credentials
Third-Party Integrations
All integrations (SharePoint, Teams, ServiceNow, Confluence, PolicyTech, EHR systems, and the contract/scheduling/HR connectors in development) are configured at the organization level by that organization’s own administrators. Connector API credentials are encrypted at rest with the organization’s own encryption key, are never returned to the browser after saving, and are decryptable only by the server-side sync services. No ePHI is transmitted to third parties without explicit configuration and BAA coverage.
Need a BAA or Have Compliance Questions?
We are ready to assist with BAA execution, security assessments, and HIPAA-related inquiries. Reach out to start the process.
Contact Compliance TeamLast updated: July 2026. This page describes our security architecture and controls. Solution Compass is HIPAA-ready and will execute a BAA with covered entities; we do not currently hold a SOC 2 Type II attestation. Our security documentation, control descriptions, and BAA terms are available on request.