Security posture
Dermhilda treats your ModMed data as protected health information from the first byte. The posture is layered, on the deliberate assumption that any single safeguard can fail and the rest should still hold. Below is the HIPAA program, and the automated controls that keep it honest day to day.
Prepared for your IT & compliance team
Where your data lives
Most platforms put every customer into one database and keep them apart with a column. We don't. Each client is provisioned into a completely separate Google Cloud project, with its own storage, its own datasets and its own service account — so there is no query, no misconfiguration and no mistake that can reach from one practice into another's data.
At rest
Encrypted storage, inside your project
In use
Identity, scoped per project
At the end
Destruction, not deactivation
The model
A Business Associate Agreement is in place before any of your data is touched — with every infrastructure provider, audited annually. From there, HIPAA's three categories of safeguard work together.
HIPAA · Technical
Encryption, identity, monitoring
HIPAA · Physical
Facilities and disks
HIPAA · Administrative
Policy, people, records
The enforcement engine
The “continuous monitoring that can isolate a compromised device” isn't a person watching a screen. It's three independent layers that escalate automatically, built on Microsoft Defender, Intune, and Entra ID — each acting on its own signal, so containment happens in seconds rather than waiting on someone to notice. An administrator still owns, reviews and tunes them — what is automated is the response, not the oversight.
Layer 01
Device compliance + Conditional Access
health check → system evaluates → access blocked
Layer 02
Automated investigation & remediation
threat detected → auto-investigate → auto-quarantine
Layer 03
Automatic attack disruption
active attack → signals correlated → device isolated
Containment doesn't wait on a person.
On a high-confidence attack signal, the affected device is isolated from the network within seconds — automatically, well inside the breach-notification window — so an incident is stopped from spreading before anyone has to notice it.
Prevent · detail
A device must pass every check below to reach corporate resources. The moment one fails, the user is notified and new sessions are blocked. When the issue is fixed, access restores on its own — no ticket required.
Device compliance — required on every managed device
| Rule | What fails it |
|---|---|
| Microsoft Defender enabled | Service stopped or disabled |
| Real-time protection | Real-time scanning off |
| Antivirus | Component missing or disabled |
| Antispyware | Component disabled |
| Windows Firewall | Firewall disabled |
| BitLocker encryption | Drive not encrypted |
| Device risk score | Flagged High or Critical |
| Signature definitions | Definitions not current |
Every connection, checked
Contain · detail
Network isolation is the highest-severity response, reserved for high-confidence signs of a real attack in progress. Everyday detections are handled by the earlier layers, so isolation stays meaningful.
High-confidence attack in progress
Routine — no isolation needed
Breach notification is governed by your Business Associate Agreement, which sets the timeline we are held to.
The crosswalk
Every line above corresponds to a specific, live mechanism — not a policy on paper, but something that runs automatically.
Safeguard → enforcement
| The safeguard | What enforces it |
|---|---|
| Encrypted at rest, AES-256 | Drive encryption required on every device before it can connect |
| Verified-push MFA at every entry | Access is granted only with verified MFA — every session |
| Minimum-necessary, named accounts | Identity-bound access; no shared logins |
| No public-facing way in; zero trust | Device and identity verified before any resource is reachable |
| Continuous monitoring & behavioral detection | Microsoft Defender on every device, with automated investigation |
| Isolate a compromised device on its own | Automatic attack disruption — network isolation in seconds |
Bring your hard questions
If your IT or compliance people have questions this doesn't answer, put us in front of them. We'll answer directly, with documentation where it matters.