EMOTIONAL WELL-BEING

Security

Protocol standard: v1.4

The platforms we build house protected health information, clinical documentation, and billing data. We apply enterprise-grade, HIPAA-aligned security practices to every deployment.

Infrastructure Security

We deploy on established cloud infrastructure providers that maintain SOC 2 Type II and HITRUST-aligned compliance, with signed Business Associate Agreements in place. All data at rest is encrypted with AES-256, and all data in transit is protected with TLS 1.3.

Application Security

  • Authentication: Hardened session management with support for multi-factor authentication on clinician and admin accounts.
  • Access control: Role-based permissions ensure a clinician, biller, or administrator can only view records their role is authorized to access.
  • Minimum necessary access: Client records are scoped to the care team directly involved in that client's treatment.
  • Audit logging: All access to protected health information is logged and available for compliance review.

Payment Security

Emotional Well-Being does not store credit card numbers on our own servers. All payment processing is handled through PCI-DSS Level 1 certified providers.

Vulnerability Reporting

If you believe you've found a security vulnerability in our systems or in a platform we've deployed for a client, please email security@emotionalwellbeing.us. We respond to all reports within 48 hours.