Security and Privacy

Designed from the start for protected health information.

Every architecture decision in Acuity was made with HIPAA controls in mind. This page explains what that means for your facility's data.

TLS 1.3
Encryption in transit
AES-256
Encryption at rest
US-only
Data residency
BAA
Included every tier

How your data is handled

  • All PHI is encrypted in transit (TLS 1.3) and at rest (AES-256).

  • Data is processed and stored in US-based infrastructure only.

  • Your facility's patient data is not used to train or improve Acuity models outside your own deployment environment. No cross-facility model training.

  • Access is scoped to role: charge nurses see their unit, administrators see their facility, Acuity staff cannot access PHI without an auditable service request.

Data flow summary

  • Patient data flows from your EHR into Acuity over an encrypted integration layer.

  • Processing occurs in an isolated tenant environment. No cross-facility data commingling.

  • Documentation outputs flow back to your EHR via the same encrypted channel.

Staff privacy and patient data controls

  • Audit logging for all access to patient-linked data fields.

  • Configurable data retention windows to match your facility policy.

  • Role-based access controls integrated with your existing credentialing system.

  • Staff interaction data is aggregated, not linked to individual employee records in reporting.

Questions for your security review

We understand healthcare security teams have detailed requirements. Common topics we address in security reviews:

  • Penetration testing and vulnerability management cadence
  • Incident response and breach notification procedures
  • Sub-processor agreements and data processing addenda
  • Disaster recovery and RTO/RPO commitments
  • Vendor access and privileged account management
Request a Security Review

HIPAA and regulatory positioning

Acuity is architected with HIPAA administrative, physical, and technical safeguard controls in mind. We execute a Business Associate Agreement (BAA) with every facility partner. We are not a covered entity -- we operate as a business associate under your facility's covered entity designation.

Our BAA covers all processing activities within the Acuity platform. Security documentation is available on request during the review and procurement process.

What we offer

  • Business Associate Agreement (BAA) with every tier
  • Architecture documentation for your security team
  • Data processing addendum upon request
  • Security review call with our engineering team

Questions about our security architecture?

Contact our security team directly at [email protected] or schedule a security review call.

Contact Us