Feature · PII
PII · security & compliance
How HeyMed protects patient and clinic data — encryption, backups, and specialist platforms — while HIPAA compliance for US customers is under active development.
We do not claim HIPAA certification today. We still design for encryption, least privilege, and audited specialists like Cloudflare, Twilio, and Stripe.
Card data stays with Stripe; SMS and video ride Twilio; compute and storage sit on Cloudflare — each with published compliance pages you can verify.
01 · Deep dive
What this feature actually is
HeyMed handles personally identifiable information (PII) and clinic operations data as part of the practice OS — schedules, CRM, messages, bills, and telehealth metadata.
We are currently under development for HIPAA compliance for our US customers. Until that program is complete, we do not claim HIPAA certification. We still design for least privilege, encryption, backups, and audited specialist platforms.
Patient charts and clinic secrets should not ride in clear SMS bodies or DIY spreadsheets. Messages stay office-name-first with STOP and privacy; payments stay tokenized with Stripe; live media rides Twilio; compute and object storage sit on Cloudflare.
This page explains the practices and the platforms — with links to each vendor’s own compliance and reliability documentation.
02 · How it works
From ask to done — one loop
Built as a real surface in the practice OS — not a brochure paragraph.
- 01 · Protect the dataEncrypt, isolate offices, and keep secrets off staff devices.
- 02 · Survive the bad dayBackups and recovery so the practice thread is not a single laptop.
- 03 · Compose audited platformsCloudflare, Twilio, and Stripe carry certifications we inherit instead of DIY.
03 · How we protect data
Practices we take seriously
Encryption, backups, least privilege, and specialist platforms — before and after HIPAA certification lands.
- 01Encrypt in transit and at rest
TLS on the edge; encrypted storage for practice data and backups — not plaintext disks in a closet.
- 02Back up and recover
Routine backups and restore drills so a bad day is not a permanent loss of the clinic’s thread.
- 03Least privilege
Office staff see their office. Platform operators wire integrations — offices never hold Twilio or Stripe secrets.
- 04Stand on specialists
Cards, SMS/voice/video, and edge compute stay with vendors that publish their own audits — we compose them instead of reinventing a weaker copy.
04 · Product illustrations
See the surface
UX-style illustrations — fictional Lumen only. Each tile echoes the real product layout without photo screenshots.
05 · What you get
Included with this building block
- Encryption in transit (TLS) and at rest for practice data
- Backups and recovery posture for clinic continuity
- Least-privilege office vs platform roles
- Cloudflare for edge compute, DNS/TLS, and storage
- Twilio for SMS and telehealth video (HIPAA-eligible products with BAA where PHI rides)
- Stripe for payments (tokens — not raw card numbers in our database)
- Clear status: HIPAA compliance under development for US customers — not a claim today
05b · Platforms
Compliant platforms we stand on
We compose specialists that publish their own audits — then link to their compliance and reliability pages so you can verify the source.
- Cloudflare Edge compute (Workers), DNS/TLS, DDoS, and object storage for the practice OS.
- Twilio SMS and telehealth video. HIPAA-eligible products with a BAA where PHI rides the wire.
- Stripe Payments — card data stays with Stripe; we keep tokens, not PANs.
06 · Why clinics care
Robust, reliable, and in the same OS
- US HIPAA in progressUnder active development for US customers — we do not claim HIPAA certification today.
- Security practices nowEncryption, backups, least privilege, and BCDR on Cloudflare + Twilio + Stripe.
- No DIY card vaultStripe tokens payments; we refuse to store PANs in a homemade ledger.
Ready to see the full platform?
Compare approaches, browse every feature, or join the waiting list.