HIPAA Compliance
We architect for the HIPAA Security Rule's administrative, physical, and technical safeguards as a baseline requirement, not an aspiration. Controls in place across our products include:
- Encryption in transit for all connections, and encryption at rest for databases, file storage, and backups using industry-standard algorithms.
- Role-based access controls that limit each user to the minimum data their job requires; administrative access within our own team follows the same least-privilege model.
- Audit logging of record access and security-relevant events with user, time, and action — a trail that supports both internal review and customer compliance obligations.
- Workforce security and privacy training.
- Documented policies for PHI handling and retention.
- Incident response and breach notification procedures.
- Periodic risk assessments across the portfolio.
Business Associate Agreements
Extrencity, Inc executes Business Associate Agreements with covered-entity customers for each product that processes PHI. Details and execution are handled through our BAA page.
SOC 2 — In Process
Extrencity, Inc is working toward SOC 2 and is in the middle of putting the required controls in place across all of our products. Enterprise prospects who want to know where we stand — which controls exist today, and on what timeline the rest will land — can simply ask: Contact Us.
Infrastructure and subprocessors
Our products run on established cloud infrastructure providers with physically secured, redundant data centers. We maintain signed Business Associate Agreements with every subprocessor that may touch PHI, so the chain of accountability is unbroken from your data to ours.
Environments are segmented, patched on a defined cadence, and monitored for anomalous activity. Backups are encrypted and tested as part of our recovery procedures.
Responsible AI
AI features across the portfolio draft, summarize, and organize — they do not make clinical or legal decisions. A qualified human reviews AI output before it becomes part of a record, a report, or an appeal.
- Customer PHI is never used to train AI models.
- Human review is built into every AI-assisted workflow.
- AI processing occurs under the same encryption and access controls as the rest of each product.
Reporting a vulnerability
Think you have identified a security flaw in an Extrencity, Inc product? Reach out through our contact form — Contact Us — with enough detail for us to reproduce what you found. We respond quickly to reports and ask only that you hold off on going public long enough for us to ship a fix.
Security documentation
Compliance teams evaluating our products can request additional detail on controls, subprocessors, and BAAs — Contact Us.