Security & compliance

Specific controls, not badges.

Cervica is built to comply with the HIPAA Security Rule. Here is exactly what that means in this product, stated plainly so you can hold us to it.

Encryption

All traffic is encrypted in transit with TLS. Data is encrypted at rest, and the most sensitive fields, such as Social Security numbers, carry an additional layer of AES-256 encryption on top of disk level encryption.

Every chart access is logged

Access to patient information writes an audit record: who, what, and when. Practice owners can review the audit log themselves inside Settings. This is the control that answers the fears that actually keep owners up at night: staff snooping and board complaints.

Role based access

Owners, providers, front desk, and billing staff each see what their role needs. Financial surfaces are permission gated separately.

Backups that have actually been restored

Automated backups run continuously, and we practice restoring them. Our most recent full restore drill completed successfully; we repeat the drill quarterly. A backup that has never been restored is a hope, not a plan.

Your data is never used to train AI models

Cervica's AI features process your data to serve you and nothing else. Patient information is not used to train ours or anyone's models.

Business Associate Agreement

We sign a BAA with every practice. Our infrastructure runs on AWS under its healthcare eligible services with our own BAA in place upstream.

Hard deletes do not exist for patient data

Patient records are deactivated, never destroyed, preserving the medical legal record your license depends on.

A note on certifications: "HIPAA certified" does not exist as a real certification, and we will never claim badges we have not earned. When third party attestations are completed, they will be listed here with the reports to back them.