All products made to order in the USA

Security at VitalWay

Your health data deserves the same security infrastructure that protects financial institutions. Here's exactly how we protect it.

Encryption Everywhere

All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Lab documents are stored in encrypted blob storage with presigned URL access — never directly accessible.

Multi-Factor Authentication

MFA is required for all provider and staff accounts. Patients are strongly encouraged to enable MFA via authenticator app, SMS, or hardware security key (WebAuthn/FIDO2).

Immutable Audit Logs

Every access to protected health information is logged in an immutable audit trail. Logs are append-only and cannot be modified or deleted by any application user.

Role-Based Access Control

Strict RBAC limits access to PHI based on clinical need. Minimum-necessary access is enforced at the database and application layer. No user role has more access than their function requires.

Infrastructure Security

Our platform runs on enterprise-grade cloud infrastructure with WAF, DDoS protection, and network-level isolation. Security headers are enforced on all routes (HSTS, CSP, X-Frame-Options).

Vendor Management

All vendors with access to PHI are required to sign Business Associate Agreements (BAAs). We maintain a vendor registry with BAA status tracking and periodic review.

Compliance standards

HIPAA

HIPAA-ready technical safeguards implemented across all PHI systems.

In Place

SOC 2 Type II

Audit preparation underway with target completion in Q4 2025.

In Progress

OWASP Top 10

Security controls address all OWASP Top 10 categories.

In Place

NIST CSF

Security program aligned to NIST Cybersecurity Framework.

In Place

Responsible Disclosure

If you discover a security vulnerability in our systems, we ask that you report it to us privately before public disclosure. We are committed to investigating and resolving reported vulnerabilities promptly.

Report vulnerabilities to: security@vitalwayhealth.com

We will acknowledge receipt within 48 hours and provide a resolution timeline. We do not take legal action against researchers who responsibly report vulnerabilities.

    Security | VitalWay Health