Your facility data is sensitive. Our security architecture is built to protect it at every layer, from infrastructure to application to AI processing.
Healthcare facility data demands the highest level of protection. Our security architecture is designed to meet the expectations of enterprise healthcare operators, REITs, and regulatory bodies.
AES-256 encryption for all stored data, including facility documents, reports, and user information.
TLS 1.3 for all data transmission. No unencrypted connections accepted.
Role-based access with principle of least privilege. Multi-factor authentication required.
INFRASTRUCTURE
Hosted on SOC 2 certified cloud infrastructure with geographic redundancy. All servers located in U.S. data centers. No facility data leaves U.S. jurisdiction.
Web application firewall (WAF), DDoS protection, intrusion detection systems, and network segmentation. All internal services communicate over encrypted channels.
Each client's facility data is logically isolated. No cross-client data access is possible at the application or database level. Tenant isolation is enforced at multiple layers.
Automated daily backups with point-in-time recovery. Backups encrypted and stored in geographically separate locations. Recovery time objective (RTO) under 4 hours.
APPLICATION
Multi-factor authentication (MFA) required for all accounts. Support for SSO/SAML integration for enterprise clients. Session management with automatic timeout.
Role-based access control (RBAC) with granular permissions. Facility-level access restrictions. Administrative actions require elevated privileges and are fully audited.
Comprehensive audit trail for all data access, modifications, and administrative actions. Logs retained for minimum 12 months. Tamper-evident log storage.
Regular penetration testing by third-party security firms. Automated dependency scanning. Responsible disclosure program. Critical vulnerabilities patched within 24 hours.
Secure SDLC practices including code review, static analysis, and security testing integrated into CI/CD pipeline. All code changes require peer review.
AI SECURITY
Your facility data is never used to train models that serve other clients. AI processing occurs in isolated environments with no cross-tenant data leakage. Model outputs are generated fresh for each assessment.
Our regulatory intelligence is built from publicly available codes, standards, and CMS guidance documents. The Regulatory Brain's knowledge base is separate from client facility data and contains no proprietary client information.
All AI-generated assessments are validated by licensed professionals with regulatory survey experience before delivery. Our system augments human expertise rather than replacing it.
COMPLIANCE
Type II
In Progress
Compliant
BAA Available
Compliant
Privacy Rights Supported
We maintain a documented incident response plan with defined escalation procedures. In the event of a security incident affecting your data:
Detection and containment within 1 hour
Client notification within 24 hours
Root cause analysis within 72 hours
Full remediation report within 7 days
Our team is available to discuss security requirements, provide documentation, or address specific concerns for your organization.
Contact Security Teamsecurity@sourcepathsystems.com
Join the Founders Cohort. 25 spots. $3,450 locked for life. September 30 deadline.