Security
1. Our approach to security
Sefton is operated by Sefton Health, Inc. and is built to support HIPAA compliance. For PHI, Sefton Health, Inc. acts as a Business Associate of the healthcare provider (the Covered Entity) and signs a Business Associate Agreement (BAA) with covered customers. We process Protected Health Information (PHI) only to provide and support the Service.
2. Technical safeguards
- Encryption in transit and at rest for PHI.
- Role-based access control with least-privilege access.
- Multi-factor and passkey/WebAuthn authentication options.
- Tenant isolation between customer practices.
- PHI-aware audit logging of access to records.
- Secrets management, security headers, and origin controls.
3. Infrastructure
The Service is hosted on Amazon Web Services (AWS) in a HIPAA-eligible configuration under a signed Business Associate Agreement. Data is processed in the United States.
4. Sub-processors and Business Associate Agreements
PHI-bearing sub-processors operate under signed Business Associate Agreements (currently AWS and Optum). Payment (Stripe), push-notification, identity, and source-control vendors are kept out of PHI scope.
For BAA or HIPAA-compliance inquiries, contact compliance@sefton.health.
5. Incident response
We maintain incident-response and breach-notification procedures consistent with HIPAA. In the event of a breach of unsecured PHI, we notify affected providers without unreasonable delay so they can meet their own notification obligations as the Covered Entity.
6. Your responsibilities
As the Covered Entity, your practice is responsible for protecting account credentials, managing user access, configuring security options such as multi-factor authentication, and obtaining the patient consents required for your use of the Service.
7. Reporting a security concern
Sefton Health, Inc. (operating the Sefton platform)
Email: security@sefton.health
© 2026 Sefton Health, Inc. All rights reserved.