Trust & Security
Our role under HIPAA
Sefton is built to support HIPAA compliance. For Protected Health Information (PHI), Sefton Health, Inc. acts as a Business Associate of your practice (the covered entity), under a signed Business Associate Agreement. Your practice controls patient PHI; we process it only to provide the service.
Safeguards
- Encryption in transit and at rest
- Access controls and least-privilege; tenant isolation
- Multi-factor and passkey (WebAuthn) authentication options
- PHI-aware audit logging and incident response
- Secrets management and security headers / origin controls
Our commitment on AI and your data
We do not sell your information, and we do not use PHI to train, fine-tune, or improve any AI or machine-learning model — first-party or third-party, general-purpose or special-purpose — except solely to deliver the feature you asked for to your own practice. This is a contractual, non-waivable commitment in our Business Associate Agreement, not just a policy statement. AI features provide administrative support only; your clinician reviews and is responsible for every note and code.
Sub-processors (PHI-bearing)
These vendors process PHI to provide the service and operate under signed Business Associate Agreements:
| Sub-processor | Scope | BAA |
|---|---|---|
| Cloud infrastructure provider | HIPAA-eligible hosting, PHI runtime, and AI/media processing when enabled | Signed |
| Optum | Clearinghouse + ERA / remittance | Signed |
Vendors kept out of PHI scope
| Vendor | Why no PHI |
|---|---|
| Stripe | Payments only — subscription/payment payloads kept PHI-free |
| Apple APNs | Push delivery — push payloads kept PHI-free |
| Google OAuth | Sign-in identity metadata only |
| GitHub | Source control — PHI never committed |
Change notice
We will update this page and provide notice by reasonable means before adding a new PHI-bearing sub-processor.
Certifications
SOC 2 Type I is in progress. We can provide available security attestations under NDA to customers on request. We do not overstate our certification status.
Reporting a concern
Security questions or reports: privacy@sefton.health. If you believe your privacy rights have been violated, you may also contact your provider (the covered entity) or the U.S. Department of Health and Human Services, Office for Civil Rights.