Retention IQ
Security & healthcare readiness

Patient data treated like it's our own.

Healthcare workflows are gated. No PHI moves until the applicable BAA, permitted data flow, minimum-necessary scope, subprocessor agreements, and eligible service configurations are verified. Synthetic, de-identified, or non-PHI data is used before those gates pass.

BAA gate
Before approved PHI flow
Minimum necessary
Workflow-specific scope
Tenant isolation
Row-Level Security
Readiness evidence
Reviewed before activation
No PHI in sales CRM
Prospect intake only
The six pillars

What healthcare readiness requires.

Six activation gates reviewed for the exact customer workflow. Passing one control does not substitute for completing the full legal, technical, and operational review.

01

Encryption everywhere

Encryption at rest, transport security, certificate handling, key ownership, and backup protection are verified against the exact production services selected for the customer workflow.

02

Access control

Per-practice data isolation is enforced through Row-Level Security. Privileged-access, MFA, support-access, and break-glass procedures are reviewed before covered data is activated.

03

Audit logging

The approved workflow defines which security and administrative events are logged, how access is reviewed, who can request an export, and what retention period the executed agreements require.

04

BAA before data moves

The public BAA is a review template. An executed agreement, applicable state-law terms, and the approved data-flow schedule must be in place before PHI moves.

05

Incident obligations

Incident contacts, escalation, evidence preservation, investigation, and legally required customer notification are documented in the executed agreement and response plan.

06

Subprocessor discipline

A potential PHI subprocessor is not activated merely because it offers a HIPAA-eligible product. The required agreement, account enrollment, eligible configuration, data region, and permitted use must all be verified first.

Infrastructure stack

Where your data actually lives.

Full subprocessor list with their compliance posture and BAA status.

Subprocessor Function Location PHI status Evidence
Supabase Potential database, auth, and storage path Confirm for approved account Parked Agreement + eligible configuration required
Twilio Potential SMS delivery path Confirm for approved account Parked Agreement + program enrollment required
Mailgun Potential transactional email path Confirm for approved account Parked Agreement + eligible configuration required
GoHighLevel Sales demo booking and prospect intake Vendor-hosted No PHI Restricted to prospect data
Hostinger Static marketing site Hosting configuration No PHI Public-site content only
Cloudflare DNS and delivery for public static assets Global edge No PHI Public-site traffic only
Final vendor agreements, account eligibility, data regions, retention, and permitted use are documented in the customer-specific security review before PHI is enabled.
Compliance roadmap

What's live · what's next.

Current

Healthcare activation gate

Covered workflows stay parked until customer agreements, data scope, consent, subprocessor readiness, and technical controls are verified.

In progress

Subprocessor readiness

Agreement and eligible-service status for each potential PHI subprocessor must be completed and evidenced before use.

Roadmap

SOC 2 Type II

Retention IQ is not currently represented as SOC 2 Type II attested. Timing will be published only after an audit engagement and observation plan are formally in place.

Roadmap

Third-party penetration testing

Scope, provider, timing, remediation expectations, and evidence-sharing terms remain to be finalized.

Future

HITRUST evaluation

A future option for enterprise healthcare requirements; no current certification claim or committed date.

Ongoing

Control evidence review

Access, incident, retention, data-flow, and vendor evidence are reviewed as the managed service moves toward broader activation.

Security FAQ

The questions every privacy officer asks.

01 Can Retention IQ process protected health information?
+
Only after a healthcare-readiness review is complete. Before PHI moves, TechStack and the covered entity must execute the applicable BAA, the exact workflow and minimum-necessary data must be approved, and every subprocessor that will touch PHI must have the required agreement and eligible service configuration in place. Until those gates pass, onboarding uses synthetic, de-identified, or non-PHI data.
02 When do you sign the BAA?
+
Before any PHI leaves the covered entity's approved system. The public document is a review template, not an executed agreement. Final terms, state-law attachments, subprocessor readiness, and the permitted data flow are confirmed during contracting.
03 What is your subprocessor compliance posture?
+
The current readiness register identifies Supabase, Twilio, and Mailgun as potential PHI subprocessors whose agreement and eligible-service status must be verified before a covered workflow is activated. GoHighLevel is restricted to sales and prospect intake in the documented architecture; patient data must not flow through that surface. A customer receives the final subprocessor schedule during security review.
04 What happens if there's a breach?
+
The executed agreement and applicable law control notification duties and timing. The security review documents incident contacts, escalation, investigation, evidence preservation, and customer notification before a covered workflow is activated.
05 Is your infrastructure SOC 2 compliant?
+
TechStack does not currently claim a Retention IQ SOC 2 Type II attestation. Vendor certifications do not make Retention IQ itself SOC 2 compliant. Current evidence and the roadmap can be discussed during a security review.
06 Can patients exercise their HIPAA rights through TechStack?
+
The covered entity remains the primary contact for patient rights requests. Retention IQ's obligations, assistance process, and response timing are documented in the executed BAA and order form for the approved workflow.
07 Where is patient data stored?
+
The exact storage region, backup policy, messaging path, retention schedule, and subprocessor configuration are confirmed in the customer-specific data-flow review. This page does not represent PHI processing as active while required subprocessor agreements or eligible-service configurations remain incomplete.

Want our complete security questionnaire?

We respond to standard vendor security questionnaires (CAIQ, SIG, HECVAT) and can provide subprocessor compliance certificates under NDA. Most practice IT directors or privacy officers complete their review in under a week with our materials in hand.

Want to walk the security posture with our team?

15-minute call with a real engineer. We'll answer subprocessor questions, BAA timing, breach response, and anything your privacy officer flagged. No sales handoff.

15 minutes · no sales pitch Works with your booking platform HIPAA · BAA available