Skip to main content

SECURITY · PRIVACY · COMPLIANCE

Built on a Zero-PHI Architecture.

We never touch, store, or process protected health information. AES-256 encryption, tenant isolation, and verifiable controls — by design.

We complementyour GPO contracts. We don't replace them — we help you use them better.

ZERO-PHI ARCHITECTUREAES-256 ENCRYPTIONSHA-256 SIGNED ACCEPTANCE

Zero-PHI Architecture

Not designed to ingest, store, or process patient data — by architecture.

AES-256 Encryption

All data encrypted in transit (TLS 1.3) and at rest.

Tenant Isolation

Row-level security ensures complete data separation between hospitals.

Security Architecture

Zero-PHI Data Protection Addendum

Replaces traditional BAA. Hospital Focus CK never acts as a Business Associate because we never access PHI.

Passwordless Authentication

Email-based magic links via Supabase Auth. No passwords stored. No SSO integration required.

Client-Side Document Generation

All PDFs generated in the browser via jsPDF. No document data touches our servers.

Privacy-First Analytics

PostHog with full text/attribute masking. CPRA non-cross-context designation. No PHI in telemetry.

Subprocessors

ProviderPurposeData
Supabase Inc.Database & AuthenticationAll business data, user profiles
Vercel Inc.Application Hosting & CDNSession data, static assets
Resend Inc.Transactional EmailEmail addresses, notification content
Stripe Inc.Payment ProcessingBilling information (we never see card numbers)
PostHog Inc.Product AnalyticsAnonymized, PHI-masked usage events only
OpenRouter Inc.AI-Assisted Content TailoringMasked tenant profile metadata (no PHI); zero-retention / no-logging configuration

Vulnerability Disclosure

Found a security issue? Good-faith security researchers are welcome to report vulnerabilities to security@hospitalfocus.net. We will acknowledge your report, investigate promptly, and will not pursue legal action against research conducted in good faith and in accordance with our disclosure policy.

Machine-readable contact per /.well-known/security.txt (RFC 9116).

Questions about our security posture?

security@hospitalfocus.net