Your health data is precious. We employ enterprise-grade security measures to keep it safe and give you complete control.
All data transmitted between your device and our servers is encrypted using TLS 1.3. Patient health data is encrypted at rest using AES-256.
ActiPatch® is fully compliant with HIPAA regulations. We maintain Business Associate Agreements (BAAs) with all partners and vendors.
Role-based access controls isolate consumer, patient, provider, and investor portals. Consumer wellness data (PII) and patient clinical data (PHI) are strictly separated. All access is logged and auditable.
Our platform runs on SOC 2 Type II certified cloud infrastructure with multiple availability zones and automatic failover.
We conduct annual third-party security audits and penetration testing. Vulnerabilities are remediated within 24-48 hours.
Our 24/7 security team monitors for threats. In case of a security incident, affected users are notified within 72 hours.
Health Insurance Portability and Accountability Act
Service Organization Control
Information Security Management
Electronic Records Compliance
We only collect data that is necessary to provide our services. You can request deletion of your data at any time.
We never sell your personal health information to third parties. Your data is used solely to improve your treatment outcomes.
You can download a complete copy of your data at any time. We provide clear explanations of how your data is used.
If you discover a security vulnerability, please report it responsibly to our security team.