Security & compliance
Cervica is built to comply with the HIPAA Security Rule. Here is exactly what that means in this product, stated plainly so you can hold us to it.
All traffic is encrypted in transit with TLS. Data is encrypted at rest, and the most sensitive fields, such as Social Security numbers, carry an additional layer of AES-256 encryption on top of disk level encryption.
Access to patient information writes an audit record: who, what, and when. Practice owners can review the audit log themselves inside Settings. This is the control that answers the fears that actually keep owners up at night: staff snooping and board complaints.
Owners, providers, front desk, and billing staff each see what their role needs. Financial surfaces are permission gated separately.
Automated backups run continuously, and we practice restoring them. Our most recent full restore drill completed successfully; we repeat the drill quarterly. A backup that has never been restored is a hope, not a plan.
Cervica's AI features process your data to serve you and nothing else. Patient information is not used to train ours or anyone's models.
We sign a BAA with every practice. Our infrastructure runs on AWS under its healthcare eligible services with our own BAA in place upstream.
Patient records are deactivated, never destroyed, preserving the medical legal record your license depends on.
A note on certifications: "HIPAA certified" does not exist as a real certification, and we will never claim badges we have not earned. When third party attestations are completed, they will be listed here with the reports to back them.