Alluxi is HIPAA compliant. We build software that handles protected health information, and we run our own company on the same standard we build to for our healthcare clients.
We maintain a documented security program with a designated security officer, written policies and procedures, and a recurring security risk analysis. Findings are tracked to remediation, and the program is reviewed as our tooling, team, and client work evolve.
Every team member completes HIPAA and security awareness training at onboarding and on a recurring basis. Access to client systems and PHI is limited to trained personnel with a need to know.
We execute a BAA with each healthcare client before any PHI flows through systems we build or operate, and we require BAAs from subcontractors and vendors that store or process PHI on our behalf.
Data is encrypted in transit and at rest. Access follows least privilege, protected by multi-factor authentication, and is logged for audit. Production data stays in production — we do not use client PHI in development or test environments.
Every change goes through code review before it ships. We keep development, staging, and production environments separated, manage dependencies for known vulnerabilities, and design audit trails and access controls into the systems we deliver.
We maintain a documented incident response plan with defined roles and escalation paths, including breach notification procedures aligned with the HIPAA Breach Notification Rule and our contractual obligations to clients.
We're glad to support your security review. Request our compliance documentation, policy summaries, or a completed security questionnaire — available under NDA.
Contact us