Security
The trust posture an ASC compliance officer asks for.
Periopilot expands the short HIPAA answer from the FAQ into the controls a procurement review actually needs — encryption posture, attestation roadmap, BAA flow, role-based access, audit log behavior, and where your data lives. Plain prose, clinical voice, matched against what your security questionnaire will ask.
Encryption
PHI is encrypted in transit and at rest by default.
Every clinical payload crosses the wire on TLS 1.2+ and lands on disk under AES-256 — including backups, log archives, and any PHI pulled into a queue for review. Keys rotate on the schedule your security policy expects, and a key-compromise event triggers immediate rotation without operational downtime for the platform.
Certifications
SOC 2 Type II in active observation; HITRUST CSF readiness underway.
Our SOC 2 Type II window is open with an independent auditor and a full year of controls evidence. HITRUST CSF readiness is in flight alongside it — the same controls are mapped so the audit artifacts you receive tell one consistent story. Both attestations ship on request, on NDA, when they are ready to share.
Business Associate Agreement
A signed BAA is executed before any PHI touches our systems.
The BAA is part of every commercial contract — no PHI enters the platform until both signatures are on file. Pilot sites sign first, then connect; evaluations against synthetic data never leave our environment. The BAA template is reviewable up front so your legal team can move at its own pace.
Role-based access
Role-based access with SSO and SCIM, scoped by center.
Access follows the least-privilege defaults an ASC expects — pre-op, intra-op, perioperative, PACU, post-op, and management roles each see only the surfaces they operate. SSO via SAML and OIDC is standard, and SCIM provisioning keeps your identity directory authoritative. New hires and access changes flow through your IdP, not ours.
Audit logging
Every read of clinical data writes to a tamper-evident audit log.
Audit entries are append-only, hash-chained, and exportable to your SIEM in the formats compliance officers already work in. Logs cover role, action, target record, time, and originating session — enough to reconstruct any review a surveyor or auditor asks for. Your compliance officer can pull the complete history on demand.
Data residency
U.S.-region infrastructure with contractual isolation per center.
PHI stays inside the United States, on HIPAA-eligible infrastructure with contractual controls attached to each center. Multi-site portfolios can be hosted as one logical tenant or separated by site, depending on the isolation posture your risk register requires. Cross-border movement is opt-in and contractual — never incidental.
Request access
Request the full security packet.
A single intake — your compliance officer fills in the questionnaire, we return the full packet on NDA within one business day. Or skip the form and email the founder directly; nothing here requires a sales call before you see the evidence.