Security & Compliance

HIPAA by design. Not by checkbox.

Security is not a feature we added after the fact. Every layer of the eLife platform was architected from the ground up to protect patient data, meet regulatory requirements, and give providers the audit trail they need.

Certifications

Built to the standards healthcare demands.

HIPAA Compliant

BAA available for all Practice and Enterprise customers. Full HIPAA compliance documentation provided at onboarding.

SOC 2 Type II

Annual third-party audit of security, availability, and confidentiality controls. Results shared under NDA on request.

AES-256 Encryption

All data encrypted at rest with AES-256 and in transit with TLS 1.3. Encryption keys rotated on a 90-day cycle.

Zero-Trust Architecture

Every request is authenticated and authorized before execution. No implicit trust inside the network perimeter.

Data Practices

Your patients' data stays yours.

eLife never monetizes patient data. These are the concrete commitments we make to every customer, backed by contract.

  • Never sold. Never shared.

    Patient data is never sold, licensed, or shared with third parties for marketing, research, or any other purpose. You own it. We process it only as directed.

  • Break-the-Glass access with audit trail.

    Emergency access to a patient record requires a documented reason code. Every break-glass event is logged, timestamped, and surfaced in your compliance dashboard.

  • US-based, HIPAA-compliant infrastructure.

    All data is stored and processed in US-based cloud infrastructure certified for HIPAA workloads. No data crosses international borders without explicit contractual authorization.

  • Right to deletion, always.

    Patients can permanently delete their profile and all associated data at any time from within the eLife app. Deletion is irreversible and completed within 30 days across all systems.

Enterprise

Additional controls for health systems.

Enterprise customers receive a dedicated security layer on top of the platform baseline, with custom agreements and implementation support.

Business Associate Agreement

A signed BAA is provided to all Practice and Enterprise customers as part of onboarding. No extra step required.

Custom Data Retention Policies

Set minimum and maximum retention windows per record type to match your compliance program and state regulations.

Dedicated Security Review

A security engineer joins your implementation to walk through your specific environment, threat model, and integration points.

Penetration Testing Results

Annual third-party pen test reports are available to Enterprise customers under NDA. Findings and remediation timelines included.

Access Control

The right people see the right records.

Granular access controls prevent over-exposure at every level, from individual providers to admin users.

  • Role-based access

    Three distinct permission levels: patient, provider, and admin. Each role sees only the data and actions relevant to their function.

  • MFA for all providers

    Multi-factor authentication is enforced for every provider account. TOTP and push notification methods supported.

  • Immutable audit trail

    Every record view, export, and edit is logged with timestamp, user ID, and IP address. Logs cannot be modified or deleted.

  • Automatic session timeout

    Provider sessions expire after a configurable idle period (default 15 minutes) and require re-authentication to resume.

Security Questions

Questions about our security practices?

Our security team responds to all inquiries within one business day. We can also arrange a dedicated security review for Enterprise evaluations.