Security at VitalWay
Your health data deserves the same security infrastructure that protects financial institutions. Here's exactly how we protect it.
Encryption Everywhere
All data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Lab documents are stored in encrypted blob storage with presigned URL access — never directly accessible.
Multi-Factor Authentication
MFA is required for all provider and staff accounts. Patients are strongly encouraged to enable MFA via authenticator app, SMS, or hardware security key (WebAuthn/FIDO2).
Immutable Audit Logs
Every access to protected health information is logged in an immutable audit trail. Logs are append-only and cannot be modified or deleted by any application user.
Role-Based Access Control
Strict RBAC limits access to PHI based on clinical need. Minimum-necessary access is enforced at the database and application layer. No user role has more access than their function requires.
Infrastructure Security
Our platform runs on enterprise-grade cloud infrastructure with WAF, DDoS protection, and network-level isolation. Security headers are enforced on all routes (HSTS, CSP, X-Frame-Options).
Vendor Management
All vendors with access to PHI are required to sign Business Associate Agreements (BAAs). We maintain a vendor registry with BAA status tracking and periodic review.
Compliance standards
HIPAA
HIPAA-ready technical safeguards implemented across all PHI systems.
SOC 2 Type II
Audit preparation underway with target completion in Q4 2025.
OWASP Top 10
Security controls address all OWASP Top 10 categories.
NIST CSF
Security program aligned to NIST Cybersecurity Framework.
Responsible Disclosure
If you discover a security vulnerability in our systems, we ask that you report it to us privately before public disclosure. We are committed to investigating and resolving reported vulnerabilities promptly.
Report vulnerabilities to: security@vitalwayhealth.com
We will acknowledge receipt within 48 hours and provide a resolution timeline. We do not take legal action against researchers who responsibly report vulnerabilities.