Security & Trust
I'd rather tell you the truth than sell you a badge. This page covers two things: how your data is protected while it's with me, and the compliance help I can offer your practice — including the parts no vendor should ever promise.
How your data is protected
To build your briefing, Dermhilda works with the data your practice already keeps in ModMed — and treats every bit of it as protected health information, because that's what it is. A Business Associate Agreement is in place before any of it is touched. That comes first, always.
From there, the posture is built in layers, on the deliberate assumption that any one safeguard can fail and the rest should still hold. Patient data is encrypted at every stage — AES-256 at rest, and encrypted in transit across a private, zero-trust network with no public-facing way in. Access follows the HIPAA "minimum necessary" standard: role-based, multi-factor at every entry, and tied to a named person for every action, with no shared logins. The machines our team works on are locked down so that patient data is never stored on them, and temporary working data is wiped on a fixed schedule rather than left to pile up. Everything is monitored around the clock, backed up in encrypted off-site copies, and governed by an incident plan that can revoke access and isolate a threat within the hour. And the whole program is put through a formal HIPAA security risk assessment every year, documented as a system of record.
The same separation that runs through the product holds here too: each provider sees only their own numbers, and what you work through with Dermhilda stays inside your practice.
That's the short version. The full posture — technical, physical, and administrative safeguards — is laid out in the security overview below.
The full posture
We build on a deliberate assumption: any single safeguard can fail, so they're layered to back each other up. HIPAA sorts them into three kinds — technical, physical, and administrative — and so do we.
Technical safeguards
Physical safeguards
Administrative safeguards
That's the posture, top to bottom. If your IT or compliance team wants the detailed version, it's a download away.
Security overview · PDF
A plain-language walk through the technical, physical, and administrative safeguards behind Dermhilda — formatted to hand to your IT or compliance team.
Download the overview (PDF)Our own posture
HIPAA compliance isn't a box you check once — it's a posture you stand up and keep: a real risk assessment, written policies, trained staff, signed agreements, and documentation you can actually produce when someone asks for it.
We've built exactly that for ourselves — the assessment, the policies, the training, the records, all run on AccountableHQ as our system of record.
If you don't become a client
If your practice takes a Practice Review and decides not to go further, we destroy your practice data within 90 days — the isolated environment we built for you goes with it. You can ask us to hold it longer while you decide, once, in writing. Otherwise it goes.
We'd rather rebuild from scratch later than sit on a practice's patient records hoping you come back.
Get started
A company handling patient data should be able to answer hard questions without flinching. Bring yours — and your IT or compliance people — and we'll answer them directly, with documentation where it matters.