HIPAA Compliance

We handle protected health information the way covered entities must: under a Business Associate Agreement.

Hospitals, clinics, labs and insurers trust us with drives full of patient records. We sign Business Associate Agreements and follow the HIPAA Security Rule throughout the recovery.

How we protect PHI

  • Business Associate Agreement signed before any device ships
  • Administrative, physical and technical safeguards under the Security Rule
  • Minimum-necessary access: only the assigned engineer touches the data
  • Encrypted return media and certified destruction of working copies
  • Breach-notification procedures aligned with the HITECH Act

Who we work with

Hospitals, physician groups, dental and imaging practices, labs, pharmacies, insurers and health-tech vendors.

Chain of custody

  1. Intake. Your device is photographed, serial-numbered and sealed in a tamper-evident bag. You get a case number and an intake record.
  2. Storage. Devices wait in a locked, access-logged vault, never on an open bench.
  3. Recovery. Only the assigned engineer can sign the device out. Every handoff is recorded with name, time and purpose.
  4. Verification. Recovered data is hashed so you can confirm nothing changed between our lab and your hands.
  5. Return. Data ships on a new encrypted drive by tracked, signature-required courier, or by secure download.
  6. Destruction. Once you confirm receipt, working copies are wiped to NIST 800-88 and you receive a certificate of destruction.

Certifications

SOC 2 Type IIIndependently audited controls
HIPAABusiness Associate Agreements
ISO Class 5 cleanroomParticle-controlled lab
Chain of custodyEvery device, every step

More on security

Every hour matters. Contact us now.

Stop using the device, then talk to an engineer. Evaluation is free and your quote is fixed before we start.