Security & Trust

You're handing me patient data. Here's how I treat it.

I'd rather tell you the truth than sell you a badge. This page covers two things: how your data is protected while it's with me, and the compliance help I can offer your practice — including the parts no vendor should ever promise.


How your data is protected

Your data, handled as what it is.

To build your briefing, Dermhilda works with the data your practice already keeps in ModMed — and treats every bit of it as protected health information, because that's what it is. A Business Associate Agreement is in place before any of it is touched. That comes first, always.

From there, the posture is built in layers, on the deliberate assumption that any one safeguard can fail and the rest should still hold. Patient data is encrypted at every stage — AES-256 at rest, and encrypted in transit across a private, zero-trust network with no public-facing way in. Access follows the HIPAA "minimum necessary" standard: role-based, multi-factor at every entry, and tied to a named person for every action, with no shared logins. The machines our team works on are locked down so that patient data is never stored on them, and temporary working data is wiped on a fixed schedule rather than left to pile up. Everything is monitored around the clock, backed up in encrypted off-site copies, and governed by an incident plan that can revoke access and isolate a threat within the hour. And the whole program is put through a formal HIPAA security risk assessment every year, documented as a system of record.

The same separation that runs through the product holds here too: each provider sees only their own numbers, and what you work through with Dermhilda stays inside your practice.

That's the short version. The full posture — technical, physical, and administrative safeguards — is laid out in the security overview below.


The full posture

The safeguards, laid out.

We build on a deliberate assumption: any single safeguard can fail, so they're layered to back each other up. HIPAA sorts them into three kinds — technical, physical, and administrative — and so do we.

Technical safeguards

The digital controls

  • Patient data is encrypted at every stage — AES-256 at rest, and encrypted in transit across a private, zero-trust network with no public-facing way in.
  • Every entry point requires verified-push multi-factor authentication. Access follows the HIPAA "minimum necessary" standard and is tied to a named person — no shared logins.
  • Endpoints are monitored continuously, with behavioral threat detection that can isolate a compromised device on its own.
  • Patient data is never stored on the machines our team works from; the work happens inside our secured environment, and temporary working data is wiped on a fixed schedule rather than left to accumulate.

Physical safeguards

The hardware

  • The systems that process patient data sit in a private, access-controlled location in the United States.
  • Drives are hardware-encrypted and keyed to the machine they're in, so a stolen disk can't be read anywhere else.
  • Retired hardware is cryptographically wiped or physically destroyed to the NIST 800-88 standard.

Administrative safeguards

The program around it

  • A formal HIPAA security risk assessment every year, documented as a system of record.
  • A Business Associate Agreement with every infrastructure provider that touches the data — Google Cloud, Microsoft, Paubox, iDrive — audited annually.
  • Access is reviewed and recertified on a fixed cycle, and offboarding revokes it within the hour.
  • Annual HIPAA and security-awareness training for everyone, required to keep access — with records retained for six years.

That's the posture, top to bottom. If your IT or compliance team wants the detailed version, it's a download away.

Security overview · PDF

The full security overview

A plain-language walk through the technical, physical, and administrative safeguards behind Dermhilda — formatted to hand to your IT or compliance team.

Download the overview (PDF)

Our own posture

A defensible HIPAA posture is hard to build. We've already built one.

HIPAA compliance isn't a box you check once — it's a posture you stand up and keep: a real risk assessment, written policies, trained staff, signed agreements, and documentation you can actually produce when someone asks for it.

HIPAA compliance seal, powered by AccountableHQ

We've built exactly that for ourselves — the assessment, the policies, the training, the records, all run on AccountableHQ as our system of record.


If you don't become a client

We don't keep data we have no reason to hold.

If your practice takes a Practice Review and decides not to go further, we destroy your practice data within 90 days — the isolated environment we built for you goes with it. You can ask us to hold it longer while you decide, once, in writing. Otherwise it goes.

We'd rather rebuild from scratch later than sit on a practice's patient records hoping you come back.

Get started

Bring your toughest questions.

A company handling patient data should be able to answer hard questions without flinching. Bring yours — and your IT or compliance people — and we'll answer them directly, with documentation where it matters.