Protected Health Information is encrypted at rest with AES-256 and in transit with TLS 1.3. PHI never leaves the customer's tenancy without an explicit, logged authorization.
We minimize PHI in every system that doesn't strictly need it. Logs, metrics, and analytics pipelines operate on deidentified data by default.
We maintain a complete PHI data flow diagram, updated with every infrastructure change. It's reviewed quarterly by both security and compliance leadership.
