HIPAA whitepaper
How Beetony by Atulo maps the HIPAA Security and Privacy Rules to product capability, point by point. Read this when prepping for an audit or a buyer's security review.
Administrative safeguards
Role-based access control inside every workspace, with four roles (company_admin, compliance_officer, developer, read_only) mapped to scoped permissions on every query. A formal workforce training program, documented periodic access reviews, and contractor BAAs for staff with production access are planned and not yet in place.
Physical safeguards
Beetony stores no data on physical media we control. Production infrastructure lives in SOC 2 Type II-certified data centers operated by our cloud providers. Office workstations have full-disk encryption and screen lock enforcement.
Technical safeguards
TLS 1.3 in transit, AES-256 at rest, append-only audit semantics enforced at the database level, SHA-256 hashes on every record for tamper evidence, role-based access in every query, and HMAC-signed webhooks. API keys are stored only as SHA-256 hashes and each key records the time it was last used.
Breach notification
We commit to customer notification within 24 hours of confirming an incident, and to assist with downstream patient notification under the standard 60-day window. A written breach response runbook, with scheduled review and tabletop exercises, is planned and not yet in place.
Patient rights via the consent ledger
The /v1/consent endpoint is the canonical record of patient AI-use consent for each customer. Patients (via you) can revoke at any time, and every subsequent audit log records a flagged consent verdict. This satisfies the HIPAA right-to-restrict requirement in an auditable form.
Documentation
Customer auditors get a packet on request including our subprocessor list and exportable evidence for every technical safeguard listed above. Beetony does not currently offer a Business Associate Agreement, and has no SOC 2 report or written incident response runbook to include. Email compliance@beetony.com to request.