HIPAA Compliant
BAA available for all Practice and Enterprise customers. Full HIPAA compliance documentation provided at onboarding.
Security & Compliance
Security is not a feature we added after the fact. Every layer of the eLife platform was architected from the ground up to protect patient data, meet regulatory requirements, and give providers the audit trail they need.
Certifications
BAA available for all Practice and Enterprise customers. Full HIPAA compliance documentation provided at onboarding.
Annual third-party audit of security, availability, and confidentiality controls. Results shared under NDA on request.
All data encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys rotated on a 90-day cycle.
Every request is authenticated and authorized before execution. No implicit trust inside the network perimeter.
Data Practices
eLife never monetizes patient data. These are the concrete commitments we make to every customer, backed by contract.
Never sold. Never shared.
Patient data is never sold, licensed, or shared with third parties for marketing, research, or any other purpose. You own it. We process it only as directed.
Break-the-Glass access with audit trail.
Emergency access to a patient record requires a documented reason code. Every break-glass event is logged, timestamped, and surfaced in your compliance dashboard.
US-based, HIPAA-compliant infrastructure.
All data is stored and processed in US-based cloud infrastructure certified for HIPAA workloads. No data crosses international borders without explicit contractual authorization.
Right to deletion, always.
Patients can permanently delete their profile and all associated data at any time from within the eLife app. Deletion is irreversible and completed within 30 days across all systems.
Enterprise
Enterprise customers receive a dedicated security layer on top of the platform baseline, with custom agreements and implementation support.
A signed BAA is provided to all Practice and Enterprise customers as part of onboarding. No extra step required.
Set minimum and maximum retention windows per record type to match your compliance program and state regulations.
A security engineer joins your implementation to walk through your specific environment, threat model, and integration points.
Annual third-party pen test reports are available to Enterprise customers under NDA. Findings and remediation timelines included.
Access Control
Granular access controls prevent over-exposure at every level, from individual providers to admin users.
Three distinct permission levels: patient, provider, and admin. Each role sees only the data and actions relevant to their function.
Multi-factor authentication is enforced for every provider account. TOTP and push notification methods supported.
Every record view, export, and edit is logged with timestamp, user ID, and IP address. Logs cannot be modified or deleted.
Provider sessions expire after a configurable idle period (default 15 minutes) and require re-authentication to resume.
Security Questions
Our security team responds to all inquiries within one business day. We can also arrange a dedicated security review for Enterprise evaluations.