Skip to main content

SECURITY · PRIVACY · COMPLIANCE

Built on a Zero-PHI Architecture.

We never touch, store, or process protected health information. AES-256 encryption, tenant isolation, and verifiable controls — by design.

We complementyour GPO contracts. We don't replace them — we help you use them better.

ZERO-PHI ARCHITECTUREAES-256 ENCRYPTIONSHA-256 SIGNED ACCEPTANCE

Zero-PHI Architecture

No patient data ingested, stored, or processed. Ever.

AES-256 Encryption

All data encrypted in transit (TLS 1.3) and at rest.

Tenant Isolation

Row-level security ensures complete data separation between hospitals.

Security Architecture

Zero-PHI Data Protection Addendum

Replaces traditional BAA. Hospital Focus CK never acts as a Business Associate because we never access PHI.

Passwordless Authentication

Email-based magic links via Supabase Auth. No passwords stored. No SSO integration required.

Client-Side Document Generation

All PDFs generated in the browser via jsPDF. No document data touches our servers.

Privacy-First Analytics

PostHog with full text/attribute masking. CPRA non-cross-context designation. No PHI in telemetry.

Subprocessors

ProviderPurposeData
Supabase (AWS)Database & AuthEmail, hospital profile, supply chain metrics (no PHI)
VercelHosting & CDNStatic assets, server functions
PostHogProduct AnalyticsMasked usage events only
ResendTransactional EmailRecipient email, alert content

Questions about our security posture?

security@hospitalfocus.net