Security posture

How your group's data is protected — the safeguards, and what enforces them.

Dermhilda treats your ModMed data as protected health information from the first byte. The posture is layered, on the deliberate assumption that any single safeguard can fail and the rest should still hold. Below is the HIPAA program, and the automated controls that keep it honest day to day.

Prepared for your IT & compliance team

Where your data lives

Your group gets its own cloud project — not a row in someone else's database.

Most platforms put every customer into one database and keep them apart with a column. We don't. Each client is provisioned into a completely separate Google Cloud project, with its own storage, its own datasets and its own service account — so there is no query, no misconfiguration and no mistake that can reach from one practice into another's data.

A separate GCP projectYour own project boundary, provisioned for your group and used for nothing else.
Your own datasetsSeparate BigQuery datasets and a dedicated service account, scoped to your project alone.
Never pooledYour data is never combined with another client's, and never used to serve anyone but you.

At rest

The data lake

Encrypted storage, inside your project

  • Practice data lands in an encrypted Cloud Storage lake that exists only inside your project
  • AES-256 at rest, on HIPAA-eligible Google Cloud services under a Business Associate Agreement
  • Queried through BigQuery datasets that belong to your project and no other

In use

Who can reach it

Identity, scoped per project

  • A dedicated service account per client; credentials are never shared across projects
  • Named, minimum-necessary human access — no shared logins, recertified on a fixed cycle
  • No PHI on worker machines; the work happens inside the secured environment

At the end

When it goes

Destruction, not deactivation

  • When an engagement ends, the project is destroyed within 90 days
  • The environment goes with it — storage, datasets, service account, and the findings themselves
  • Coming back later means building from scratch again. That is the point, not an oversight

The model

Defense in depth, handled as PHI.

A Business Associate Agreement is in place before any of your data is touched — with every infrastructure provider, audited annually. From there, HIPAA's three categories of safeguard work together.

PHI, handled as PHIA BAA is signed before data is touched, with every provider that touches it.
Layered defenseTechnical, physical, and administrative safeguards, none trusted to be enough alone.
Zero trustEvery device and access request is verified before it reaches your data.

HIPAA · Technical

The digital controls

Encryption, identity, monitoring

  • AES-256 at rest; encrypted in transit over a private, zero-trust network with no public-facing entry
  • Verified-push MFA at every entry point; minimum-necessary, named accounts — no shared logins
  • Continuous endpoint monitoring with behavioral detection that can isolate a compromised device on its own
  • No PHI stored on worker machines; temporary working data wiped on a fixed schedule

HIPAA · Physical

The hardware

Facilities and disks

  • Processing systems sit in a private, access-controlled location in the United States
  • Drives are hardware-encrypted and keyed to their machine — a stolen disk can't be read elsewhere
  • Retired hardware is cryptographically wiped or destroyed to the NIST 800-88 standard

HIPAA · Administrative

The program around it

Policy, people, records

  • A formal HIPAA security risk assessment every year, kept as a system of record
  • BAAs with every provider that touches data — Google Cloud, Microsoft, Paubox, iDrive
  • Access reviewed and recertified on a fixed cycle; offboarding revokes it within the hour
  • Annual HIPAA & security-awareness training, records retained for six years

The enforcement engine

Three automated layers — prevent, remediate, contain.

The “continuous monitoring that can isolate a compromised device” isn't a person watching a screen. It's three independent layers that escalate automatically, built on Microsoft Defender, Intune, and Entra ID — each acting on its own signal, so containment happens in seconds rather than waiting on someone to notice. An administrator still owns, reviews and tunes them — what is automated is the response, not the oversight.

Layer 01

Prevent Block access

Device compliance + Conditional Access

Trigger
A device fails any minimum security check
Response
Corporate access blocked automatically — no admin action

health check → system evaluates → access blocked

Layer 02

Remediate Clean up

Automated investigation & remediation

Trigger
Malware, suspicious process, or other threat detected
Response
At high confidence: quarantine files, kill processes, reverse changes

threat detected → auto-investigate → auto-quarantine

Layer 03

Contain Isolate

Automatic attack disruption

Trigger
Active attack — ransomware, lateral movement, credential theft
Response
Device cut from the network within seconds; all sessions dropped

active attack → signals correlated → device isolated

Containment doesn't wait on a person.

On a high-confidence attack signal, the affected device is isolated from the network within seconds — automatically, well inside the breach-notification window — so an incident is stopped from spreading before anyone has to notice it.

Prevent · detail

What “compliant” means — and what enforces it.

A device must pass every check below to reach corporate resources. The moment one fails, the user is notified and new sessions are blocked. When the issue is fixed, access restores on its own — no ticket required.

Device compliance — required on every managed device

RuleWhat fails it
Microsoft Defender enabledService stopped or disabled
Real-time protectionReal-time scanning off
AntivirusComponent missing or disabled
AntispywareComponent disabled
Windows FirewallFirewall disabled
BitLocker encryptionDrive not encrypted
Device risk scoreFlagged High or Critical
Signature definitionsDefinitions not current

The access gate

Every connection, checked

  • Grant requires both: verified MFA and a compliant device
  • Identity-bound: every action ties to a named person
  • Re-checked regularly, not just at first sign-in

Contain · detail

What trips containment — and what doesn't.

Network isolation is the highest-severity response, reserved for high-confidence signs of a real attack in progress. Everyday detections are handled by the earlier layers, so isolation stays meaningful.

Isolates the device

High-confidence attack in progress

  • Active ransomware encrypting files
  • An attacker actively controlling the device
  • Lateral movement toward other devices
  • Credential theft from memory
  • Mass file-encryption behavior
  • Backup / shadow-copy deletion

Handled by earlier layers

Routine — no isolation needed

  • Device out of compliance → Prevent
  • A virus quarantined normally → Remediate
  • A suspicious file blocked → Remediate
  • Phishing email → mail protection

Breach notification is governed by your Business Associate Agreement, which sets the timeline we are held to.

The crosswalk

Each safeguard, mapped to the control that keeps it.

Every line above corresponds to a specific, live mechanism — not a policy on paper, but something that runs automatically.

Safeguard → enforcement

The safeguardWhat enforces it
Encrypted at rest, AES-256Drive encryption required on every device before it can connect
Verified-push MFA at every entryAccess is granted only with verified MFA — every session
Minimum-necessary, named accountsIdentity-bound access; no shared logins
No public-facing way in; zero trustDevice and identity verified before any resource is reachable
Continuous monitoring & behavioral detectionMicrosoft Defender on every device, with automated investigation
Isolate a compromised device on its ownAutomatic attack disruption — network isolation in seconds

Bring your hard questions

We'd rather show you how it works than hand you a badge.

If your IT or compliance people have questions this doesn't answer, put us in front of them. We'll answer directly, with documentation where it matters.