Trust
Security
The standard workup asks for no patient identifiers: no name, date of birth or record number. A session launched from Epic reads chart data, which is protected health information; DisEASE uses it for that session and does not keep it.
What is true today
Each of these already appears in the compliance answer on our FAQ or in the integration document submitted to Epic.
- No identifiers in the standard workup
- The standard workup asks for structured clinical signals: age, labs, vitals, comorbidities, allergies and current therapy. It does not ask for a name, a date of birth or any other identifier, and the interface says so at the point of entry. Do not enter patient-identifying information.
- Chart data is not retained
- In an Epic-launched session, chart data populates the workup and is evaluated by the rules for the duration of that session, then is not retained. The only record kept is a minimal audit entry naming the clinician, the timestamp, the disease module and the source EHR. It contains no chart data.
- Encryption in transit and at rest
- TLS in transit and encryption at rest across infrastructure components. Infrastructure is hosted on Amazon Web Services using HIPAA-eligible services.
- Least privilege, and only the data a rule uses
- Every scope the integration requests maps to a workup field or a rule input. The requested scopes are fixed in code, so changing them takes a release. The integration is read-only and requests no clinical notes or documents and no insurance or coverage information.
- Administrative access is restricted and logged
- Access to production infrastructure is limited and recorded. Security concerns go to security@diseaseease.com.
- Built to HIPAA security standards
- DisEASE's standard workup is designed so PHI never enters the system: you enter de-identified clinical data only. In EHR-launched sessions, chart data pre-fills the workup for the duration of the session and is not retained after the session ends. Our infrastructure is built to HIPAA security standards, all data transmission is encrypted, and we never store patient-identifying information.
What we have not done
A trust page that lists only what it has is not one. These are the gaps as they stand.
- No SOC 2 and no HITRUST. Neither audit has been performed. We will say so plainly rather than describe a posture as though it were certified.
- There is no HIPAA certification to hold. HIPAA has no certifying body. Any vendor claiming to be HIPAA certified is describing something that does not exist. What can be said is that infrastructure is built to HIPAA security standards, which is what we say.
- No independent security audit has been published. If one is commissioned, its existence and scope will appear here.
- Business associate agreements are handled case by case. There is no standing BAA offering. Ask us and we will tell you where that stands for your situation.
Send the security questionnaire
We will answer it, and we will answer the questions this page does not.