Security & Compliance Architecture
Tabula Medica is built with healthcare security and compliance as foundational principles. Protected health information (PHI) is handled under a Business Associate Agreement (BAA) on HIPAA-eligible cloud infrastructure.
Security Controls
Core security measures implemented across all environments.
Encryption
- AES-256-GCM for PHI at rest
- TLS 1.2+ for data in transit
- Field-level encryption for sensitive data
- Secure key management (AWS KMS/GCP KMS)
Access Control
- Role-based access control (RBAC)
- Multi-factor authentication (MFA)
- Session timeout enforcement
- Least-privilege principle
Audit Logging
- HIPAA-compliant audit trails
- PHI access logging
- 7-year log retention
- Tamper-evident log storage
Data Protection
- PHI redaction in logs
- Data minimization practices
- Secure data disposal
- Backup encryption
Compliance Framework
Regulatory and industry standards adherence.
HIPAA-Aligned FHIR R4 SMART on FHIR SOC 2 Roadmap HL7 v2 GDPR Ready CCPA Ready
Note: Designed for HIPAA-eligible cloud services under BAA for pilots. SOC 2 Type II audit scheduled Q2 2026.
AI Safety & NO-CDS Policy
Clinical Decision Support (CDS) is disabled per HIPAA/SOC 2 compliance requirements. All AI features provide educational information and operational insights only — never clinical recommendations.
- AI guardrails detect and refuse medical advice requests
- All AI outputs include explicit disclaimers
- Operational predictions for scheduling/resources only
- Patient insights are educational, not diagnostic
For security inquiries or compliance documentation requests, contact security@tabulamedica.com.
Take Control of Your Health Records
Unified, summarized, deduplicated, and shareable — all in one place.
Get Started