Security & Compliance

Clinical trust,
engineered in.

WoundCharts is built to the standard clinical documentation demands: HIPAA-aligned safeguards, SOC 2 Type 2 controls, and encryption at every layer.

HIPAA-alignedSOC 2 Type 2AES-256 at restTLS 1.2+ in transit

How we protect your data

Security is not a feature we bolt on. It shapes how records are stored, how access is granted, and how every action is tracked.

HIPAA compliance

WoundCharts is designed to support HIPAA-covered workflows. We execute Business Associate Agreements with covered entity customers and maintain the administrative, physical, and technical safeguards required for Protected Health Information.

SOC 2 Type 2

Our platform undergoes an annual SOC 2 Type 2 audit covering security, availability, confidentiality, and processing integrity, with reports available to customers under NDA.

Encryption everywhere

Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Photos, documents, and clinical records are encrypted the moment they leave the device.

Role-based access

Every user authenticates against their role. Clinicians see only the records their role permits, and administrators control who can create, read, update, or delete across the organization.

Hardened infrastructure

We run on cloud infrastructure with continuous monitoring, automated patching, and isolated tenant data stores. Production access is least-privilege and fully audited.

Audit trails

Every read, write, and export of a record is logged with the user, timestamp, and action, giving you a defensible chain of custody for every chart entry.

Operational practices

Workforce training

All personnel with any access path to PHI complete HIPAA security and privacy training at onboarding and annually thereafter.

Business continuity

Automated backups and documented recovery procedures keep your data recoverable and your practice running through incidents.

Data retention & deletion

Retention windows follow your agreement and applicable regulation. On termination, customer data is securely deleted on the documented schedule.

Need our compliance documentation?

Request our SOC 2 Type 2 report, BAA, or a security review under NDA.

Contact our team