Security & Compliance
WoundCharts is built to the standard clinical documentation demands: HIPAA-aligned safeguards, SOC 2 Type 2 controls, and encryption at every layer.
Security is not a feature we bolt on. It shapes how records are stored, how access is granted, and how every action is tracked.
WoundCharts is designed to support HIPAA-covered workflows. We execute Business Associate Agreements with covered entity customers and maintain the administrative, physical, and technical safeguards required for Protected Health Information.
Our platform undergoes an annual SOC 2 Type 2 audit covering security, availability, confidentiality, and processing integrity, with reports available to customers under NDA.
Data is encrypted in transit using TLS 1.2+ and at rest using AES-256. Photos, documents, and clinical records are encrypted the moment they leave the device.
Every user authenticates against their role. Clinicians see only the records their role permits, and administrators control who can create, read, update, or delete across the organization.
We run on cloud infrastructure with continuous monitoring, automated patching, and isolated tenant data stores. Production access is least-privilege and fully audited.
Every read, write, and export of a record is logged with the user, timestamp, and action, giving you a defensible chain of custody for every chart entry.
All personnel with any access path to PHI complete HIPAA security and privacy training at onboarding and annually thereafter.
Automated backups and documented recovery procedures keep your data recoverable and your practice running through incidents.
Retention windows follow your agreement and applicable regulation. On termination, customer data is securely deleted on the documented schedule.
Request our SOC 2 Type 2 report, BAA, or a security review under NDA.
Contact our team