Security overview

Security you can explain
to your privacy officer

Healthcare buyers need more than a logo lock. Here is how we approach encryption, agreements, logging, and operational transparency.

  • BAA included
  • AES-256 aligned
  • Audit logs
  • MFA for staff

Business Associate Agreement

BAA included on every plan

Your vendor relationship should be documented before PHI moves—not negotiated after an audit letter arrives. Every Easy MD Forms subscription includes a signed Business Associate Agreement executed during onboarding.

When it happens

Digital BAA signing is part of rollout—typically before your first secure email, fax, or form submission. You receive an executed copy for your compliance file.

What it covers

One agreement spans HIPAA email, cloud fax, patient forms, secure files, and team chat. You are not stacking separate BAAs for each module.

What is inside

  • Permitted uses and disclosures of PHI
  • Safeguard and breach-notification obligations
  • Subcontractor flow-down requirements
  • PHI return or destruction at termination

For your privacy officer

Request our security and compliance packet for vendor due diligence—architecture summary, subprocessors, and control overview alongside the executed BAA.

All plans include a signed BAA · Public pricing · Built for physician offices

Security controls

How we protect PHI

Technical and operational safeguards mapped to what clinics ask during vendor due diligence—not marketing fluff.

Business Associate Agreement

Every plan includes a signed BAA before you send your first message—so your compliance file is audit-ready, not assembled after a close call.

Encryption in transit

TLS protects data in transit between clients and our services. PHI stays on purpose-built channels—not consumer Gmail or personal SMS workflows.

Encryption at rest

AES-256 aligned storage practices for protected content at rest, with key management appropriate to healthcare workloads.

Access controls

Role-based access and session timeouts help limit PHI exposure to staff who need it—principle of least privilege for day-to-day operations.

Audit logging

Activity logging helps answer “who touched this PHI?” Unified logs across email, fax, and forms reduce scramble compared to patchwork tools.

Authentication & MFA

Staff admin accounts support two-factor sign-in. Customer portal users verify with a one-time code emailed after password sign-in. We recommend MFA for every account with PHI or configuration access.

Backup & recovery

Backups and recovery procedures aligned to healthcare uptime expectations—documented for vendor reviews on request.

Incident response

Documented incident response and breach notification process with customers, including coordination when a reportable event is discovered.

Email authentication

Production domains should publish SPF, DKIM, and DMARC to reduce spoofing and improve deliverability. Your hosting team can verify records with standard DNS tools.

Infrastructure transparency

What we document for buyers

Healthcare organizations deserve clear answers during vendor review—not vague assurances.

Hosting environment

Documented architecture overview and subprocessor list available on request for vendor due diligence.

Redundancy & failover

Infrastructure designed for resilience with documented backup and recovery procedures—not a single undocumented point of failure.

Monitoring

Infrastructure monitoring for availability and security-relevant events, with alerting when operational thresholds are crossed.

Vendor transparency

Security and compliance packet available on request—architecture summary, subprocessors, and control overview for your privacy officer.

Compliance standards

What we align with

HIPAA Privacy Rule

Controls on use and disclosure of PHI. BAA execution for covered services before production use.

HIPAA Security Rule

Administrative, physical, and technical safeguards implemented and documented for systems that handle PHI.

HITECH & Omnibus

Breach notification requirements and expanded Business Associate obligations under the Omnibus Rule.

NIST-aligned practices

Risk assessment and safeguard documentation informed by NIST guidance for HIPAA Security Rule implementation.

Secure communications

Purpose-built email, fax, forms, chat, and files—separate from consumer apps that lack BAAs and audit trails.

Due diligence support

Plain-language answers for practice managers and privacy officers evaluating vendors—not security jargon alone.

Third-party attestation

What we do—and do not—claim publicly

Plenty of vendors display SOC 2 and HITRUST badges. We display what we've actually earned. Request our security and compliance packet for control documentation, sub-processor details, and an honest picture of where we stand.

Available today

  • Signed Business Associate Agreement on every plan
  • Documented technical and administrative safeguards
  • Security packet for vendor due diligence (on request)
  • Subprocessor list and architecture summary (on request)

Not claimed unless formally obtained

  • SOC 2 Type II certification badges
  • HITRUST CSF validation
  • Self-reported “HIPAA posture scores” or percentage meters
  • Named customer logos without written approval

Verify our public site

Third-party scanners help confirm headers and performance on the marketing site (results vary by CDN settings):

Protect your practice

Start with a security-first platform

Get HIPAA-compliant email, fax, and forms with transparent pricing—starting with a free consult or risk check.

✓ BAA included  ·  ✓ Public pricing  ·  ✓ Built for clinics