Patient data treated like it's our own.
Healthcare workflows are gated. No PHI moves until the applicable BAA, permitted data flow, minimum-necessary scope, subprocessor agreements, and eligible service configurations are verified. Synthetic, de-identified, or non-PHI data is used before those gates pass.
What healthcare readiness requires.
Six activation gates reviewed for the exact customer workflow. Passing one control does not substitute for completing the full legal, technical, and operational review.
Encryption everywhere
Encryption at rest, transport security, certificate handling, key ownership, and backup protection are verified against the exact production services selected for the customer workflow.
Access control
Per-practice data isolation is enforced through Row-Level Security. Privileged-access, MFA, support-access, and break-glass procedures are reviewed before covered data is activated.
Audit logging
The approved workflow defines which security and administrative events are logged, how access is reviewed, who can request an export, and what retention period the executed agreements require.
BAA before data moves
The public BAA is a review template. An executed agreement, applicable state-law terms, and the approved data-flow schedule must be in place before PHI moves.
Incident obligations
Incident contacts, escalation, evidence preservation, investigation, and legally required customer notification are documented in the executed agreement and response plan.
Subprocessor discipline
A potential PHI subprocessor is not activated merely because it offers a HIPAA-eligible product. The required agreement, account enrollment, eligible configuration, data region, and permitted use must all be verified first.
Where your data actually lives.
Full subprocessor list with their compliance posture and BAA status.
| Subprocessor | Function | Location | PHI status | Evidence |
|---|---|---|---|---|
| Supabase | Potential database, auth, and storage path | Confirm for approved account | Parked | Agreement + eligible configuration required |
| Twilio | Potential SMS delivery path | Confirm for approved account | Parked | Agreement + program enrollment required |
| Mailgun | Potential transactional email path | Confirm for approved account | Parked | Agreement + eligible configuration required |
| GoHighLevel | Sales demo booking and prospect intake | Vendor-hosted | No PHI | Restricted to prospect data |
| Hostinger | Static marketing site | Hosting configuration | No PHI | Public-site content only |
| Cloudflare | DNS and delivery for public static assets | Global edge | No PHI | Public-site traffic only |
What's live · what's next.
Healthcare activation gate
Covered workflows stay parked until customer agreements, data scope, consent, subprocessor readiness, and technical controls are verified.
Subprocessor readiness
Agreement and eligible-service status for each potential PHI subprocessor must be completed and evidenced before use.
SOC 2 Type II
Retention IQ is not currently represented as SOC 2 Type II attested. Timing will be published only after an audit engagement and observation plan are formally in place.
Third-party penetration testing
Scope, provider, timing, remediation expectations, and evidence-sharing terms remain to be finalized.
HITRUST evaluation
A future option for enterprise healthcare requirements; no current certification claim or committed date.
Control evidence review
Access, incident, retention, data-flow, and vendor evidence are reviewed as the managed service moves toward broader activation.
The questions every privacy officer asks.
01 Can Retention IQ process protected health information? +
02 When do you sign the BAA? +
03 What is your subprocessor compliance posture? +
04 What happens if there's a breach? +
05 Is your infrastructure SOC 2 compliant? +
06 Can patients exercise their HIPAA rights through TechStack? +
07 Where is patient data stored? +
Want our complete security questionnaire?
We respond to standard vendor security questionnaires (CAIQ, SIG, HECVAT) and can provide subprocessor compliance certificates under NDA. Most practice IT directors or privacy officers complete their review in under a week with our materials in hand.
Want to walk the security posture with our team?
15-minute call with a real engineer. We'll answer subprocessor questions, BAA timing, breach response, and anything your privacy officer flagged. No sales handoff.