🚀 Decoda raises $4.5M, led by Y Combinator. Read more

Security & Privacy

Security and privacy at Decoda Health

Clinics trust Decoda with some of their patients' most sensitive information. Protecting that information is foundational to how we build and operate our platform.

HIPAA compliant
Privacy by design
SOC 2 Type 2 in progress

Our approach

Patient data should remain private and secure, be available when clinics need it, and be accessible only to the people authorized to use it.

Following one request

From the front desk to the disk.

Every safeguard on this page shows up somewhere along this path.

  1. Clinic browser

    Decoda is reached through the browser, so patient data stays in our cloud rather than on the laptops used to open it.

    ↓ Encrypted in transit

  2. Identity and access

    Every request comes from a trusted identity, authenticated with MFA, and scoped to what that person's role needs.

    ↓ Written to an audit log

  3. Google Cloud

    Enterprise-grade infrastructure, with each clinic's data logically isolated so it stays separate from every other clinic's.

    ↓ Encrypted at rest

  4. Storage

    Stored redundantly across geographically separated infrastructure, so availability never depends on a single copy.

01

How we protect patient data

Decoda is HIPAA compliant, and we design our platform around protecting sensitive patient information at every stage.

That starts with limiting access to the people who need it, protecting data both when it is stored and when it moves between systems, and continuously monitoring the safeguards we put in place. We are also pursuing SOC 2 Type 2 attestation, which will provide an independent, third-party assessment of how our security controls operate over time.

  • HIPAA compliant
  • SOC 2 Type 2 in progress
  • Continuous monitoring
02

Secure, cloud-based infrastructure

Decoda is hosted on Google Cloud, giving the platform the security, reliability, and resilience of enterprise-grade cloud infrastructure.

Each clinic’s data is logically isolated within Decoda, so its information remains separate from other clinics’ data. Because Decoda is accessed through the browser, patient data stays within our secure cloud environment rather than being stored on the laptops or devices used to access it.

  • Google Cloud
  • Per-clinic logical isolation
  • No patient data on devices
03

Data protection and encryption

Patient data is encrypted both in transit and at rest, protecting it while it moves between systems and while it is stored.

Data is also stored redundantly across geographically separated infrastructure. This means the availability of patient information does not depend on a single copy or physical location, helping keep it both protected and accessible when clinics need it.

  • Encrypted in transit
  • Encrypted at rest
  • Geographically redundant
04

Access and authentication

Not everyone who uses Decoda needs access to the same information. Access is limited based on role, so people can reach only the patient data they need to do their jobs.

Every request must come from a trusted identity and be authenticated with multi-factor authentication before access is granted. Remote desktop and shell access are not exposed to the public internet. For clinics that want an additional layer of control, we can also restrict access to approved IP addresses on request.

  • Role-based access
  • Multi-factor authentication
  • No public shell or remote desktop
  • IP allowlisting on request
05

Visibility and accountability

Clinics should be able to understand what happens to patient information in Decoda—not simply trust that it is protected behind the scenes.

Activity involving patient records is captured in audit logs, including when records are created, edited, or deleted. Actions are tied to individual, authenticated users, creating a clear record of who did what and when. We also continuously monitor our systems for known vulnerabilities.

  • Audit logs on patient records
  • Per-user attribution
  • Vulnerability monitoring
06

Building security into the product

Security is part of how we build Decoda, not something added after a feature is finished.

Changes to the platform are reviewed and tested before they reach production, with code review and version control applied to application changes. This helps us improve the product while reducing the risk that new functionality introduces security issues.

  • Code review
  • Version control
  • Tested before production

Have a security question?

We're here to help.

We're happy to provide additional information to customers and prospective customers evaluating Decoda.

security@decodahealth.com

See also our Privacy Policy and Terms & Conditions.