HealixAI Logo

Trust Center & Security Architecture

Enterprise-grade administrative, technical, and physical safeguards for protected health information (PHI).

Encryption Standards

All PHI data is encrypted at rest using AES-256 with key management via AWS KMS / Google Cloud KMS, and encrypted in transit using TLS 1.3.

Row-Level Data Isolation

Logical data separation enforced by PostgreSQL Row-Level Security (RLS) policies ensures zero cross-tenant PHI exposure across multi-tenant deployments.

HIPAA & SMART-on-FHIR Compliance

  • OAuth 2.0 & OpenID Connect: Secure user authentication for EHR logins without storing patient passwords.
  • De-identified AI Queries: No PHI is transmitted to standard search APIs; external queries to PubMed/Medline are sanitized.
  • Audit Logging: Comprehensive, tamper-evident audit trails tracking all data access, export, and deletion events.
Healix AI, Inc. / HealixAI, LLC