Security you cantrust

We understand just how important cyber security is in healthcare. That’s why we’ve done things differently.
Ilustración de un hombre con los brazos cruzados y una mujer a su lado
Cyber security can be complex. We keep it simple: we don't
store PHI. That means no loopholes, vulnerabilities, or risks that could expose patient data—because there’s nothing to be exposed.
/ 01
We know industry standards
HIPAA is constantly changing. That’s why we stay up-to-date on HIPAA and its security and privacy requirements for you. In fact, as part of our community, we help you understand and navigate these changes.
Ilustración de una enfermera y un médico debajo de los logotipos de RGPD, HIPAA y AICPA SOC 2
/ 02
Patient visits are incognito
Patients don’t create accounts, logins, or any other trackable information. The only way patients can be identified is through the call by you, their provider. Since the call doesn’t store PHI, patients remain anonymous.
Ilustración de una persona en una videollamada sosteniendo un cartel con un signo de interrogación, con el texto “No se necesita cuenta, inicio de sesión ni descarga de software.”
/ 03
A BAA is arranged for you
Having a business associate agreement (BAA) with your telehealth platform is a HIPAA requirement. Because we keep track of the details in telehealth security, we provide a BAA, ready for you to sign.
Ilustración de una mano firmando un documento titulado “BAA”.
/ 04
Cyber security is routine for us
Keeping our systems and software secure is a continuous process. That’s why we have processes in place that prevent intruders. And since we’re immediately alerted when there are issues, we can act quickly.
Ilustración de dos personas mirando íconos de advertencia relacionados con las conexiones a internet y la nube.
Ilustración de una enfermera y un médico debajo de los logotipos de RGPD, HIPAA y AICPA SOC 2
What to expect from our security
Ícono de una persona dentro de un marco con un signo de exclamación, que sugiere una alerta o atención relacionada con la identificación del usuario.
24/7 monitoring
With 24/7 monitoring, we can respond immediately to any security breach or suspicious activity.
Ícono de un candado y una llave
True end-to-end encryption
All chat messages and video calls sent through doxy.me remain private.
Ícono de un candado y una llave
Single sign-on
For added security, you can enable single sign-on to protect access to your account.
Ícono de una estrella con una insignia de seguridad
Dedicated security team
We have an information security team that is focused on staying ahead of cybersecurity threats.
Ícono de un escudo con una marca de verificación dentro de un marco circular, que representa protección o seguridad verificada.
Vulnerability scans
We proactively look for vulnerabilities, which reduces the risk of attacks.
Leading security standards—worldwide
HIPAA
HIPAA
We meet US standards for protecting patient health information.
AICPA SOC (System and Organization Controls)
SOC 2 (Type 2)
This industry standard report was issued by an independent auditor.
AICPA SOC (System and Organization Controls)
SOC 3
See this third-party security assessment.
Ícono de un candado con el contorno del estado de California
CPRA
We meet the requirements of the California Privacy Rights Act.
GDPR
GDPR
We meet the EU’s standards for protecting European citizens’ data.