Security at ActiPatch®

Your health data is precious. We employ enterprise-grade security measures to keep it safe and give you complete control.

End-to-End Encryption

All data transmitted between your device and our servers is encrypted using TLS 1.3. Patient health data is encrypted at rest using AES-256.

HIPAA Compliance

ActiPatch® is fully compliant with HIPAA regulations. We maintain Business Associate Agreements (BAAs) with all partners and vendors.

Access Controls

Role-based access controls isolate consumer, patient, provider, and investor portals. Consumer wellness data (PII) and patient clinical data (PHI) are strictly separated. All access is logged and auditable.

Secure Infrastructure

Our platform runs on SOC 2 Type II certified cloud infrastructure with multiple availability zones and automatic failover.

Regular Audits

We conduct annual third-party security audits and penetration testing. Vulnerabilities are remediated within 24-48 hours.

Incident Response

Our 24/7 security team monitors for threats. In case of a security incident, affected users are notified within 72 hours.

Certifications & Compliance

HIPAA

Health Insurance Portability and Accountability Act

SOC 2 Type II

Service Organization Control

ISO 27001

Information Security Management

FDA 21 CFR Part 11

Electronic Records Compliance

Data Privacy Practices

Data Minimization

We only collect data that is necessary to provide our services. You can request deletion of your data at any time.

No Data Selling

We never sell your personal health information to third parties. Your data is used solely to improve your treatment outcomes.

Transparency

You can download a complete copy of your data at any time. We provide clear explanations of how your data is used.

Report a Security Issue

If you discover a security vulnerability, please report it responsibly to our security team.