HIPAA-aligned controls
Administrative, physical, and technical safeguards mapped to the HIPAA Security Rule. Signed BAA available with every paid plan.
Security & HIPAA
Compliance isn’t a checkbox. The Pod Dispatch enforces HIPAA-grade controls at the workflow level, every day, every user, every run.
Administrative, physical, and technical safeguards mapped to the HIPAA Security Rule. Signed BAA available with every paid plan.
A signed BAA is included with every paid plan. We accept your paper or provide ours; either way, it ships before go-live.
PHI is encrypted in transit (TLS 1.2+) and at rest using industry-standard AES-256. Database backups are encrypted with separately managed keys.
Role-based access, 30-minute inactivity auto-logout, mandatory reason capture on overrides, and a full audit log of every high-risk action.
US-based, hosted with reputable cloud providers. Strict multi-tenant isolation keeps your data invisible to any other company.
Documented incident response plan with defined customer notification timelines aligned to HIPAA Breach Notification requirements.
Current list of subprocessors available on request. We notify customers in advance of material changes.