01Overview#
Clinics trust Modulon with their patients' information and their day-to-day operations: the calls they answer, the schedule, the inbox, refills, claims and payments. We treat security as part of the product, not a layer on top of it.
This page describes how we protect data, control access, govern the AI, and respond when something goes wrong. It reflects the commitments in our Business Associate Agreement and Data Processing Agreement, one of which every clinic signs before any patient information is shared.
02Security program#
- A named security officer who owns the program and reports on it to company leadership.
- Written security and privacy policies, built on the HIPAA Security Rule, the NIST Cybersecurity Framework and ISO/IEC 27001, mapped to each region's health data standards, and reviewed every year.
- A risk analysis every year and after any major change, with a tracked plan to reduce each risk it finds.
- An inventory of the systems that hold customer data, and a map of how data moves between them.
- A Business Associate Agreement or Data Processing Agreement with every clinic, and with every subprocessor that handles patient data.
03Infrastructure#
- Each clinic's data is kept in its own region: the United States, the European Union, the United Kingdom, or the Gulf, where data for the UAE, Qatar, Saudi Arabia and Kuwait stays in the clinic's own country. Patient data does not leave that region, except as the clinic's data protection terms allow.
- We run on Google Cloud in the United States and Europe, and on Microsoft Azure in the Gulf, in data centers with independently audited physical and environmental controls.
- Production runs in its own isolated environment, separate from development and testing, with private networking and no direct access from the internet to databases or internal services.
- Infrastructure is defined in code and changed only through reviewed deployments, so every change is recorded and can be rolled back.
- Traffic to the platform passes through managed load balancing with protection against denial-of-service attacks and common web exploits.
The providers we rely on, and what each one does, are listed on our subprocessors page.
04Data protection#
Encryption
- All data is encrypted in transit with TLS 1.2 or higher, and at rest with AES-256.
- Encryption keys are held in a managed key service, rotated on a schedule, and never stored with data.
- Secrets such as integration credentials are kept in a dedicated secret store, never in code.
Separation
- Each clinic's data is logically separated, and every request is checked against the clinic it belongs to, in the database as well as in the application.
- Test and development environments never contain real patient data.
Backups and recovery
- Databases are backed up continuously, with point-in-time recovery.
- Backups are encrypted, kept in a separate location, and restored regularly to prove they work.
- Our contingency plan sets targets for restoring service and data, and we test it every year.
Retention and deletion
- Clinics can export their data at any time while their subscription is active, and for 30 days after.
- When a clinic leaves, its data is deleted within 60 days of the end of its agreement, and from backups as they expire within 90 days, with written certification on request.
- Visit audio recorded by the AI note taker is deleted once the provider signs the note, unless the clinic chooses to keep it.
05Access control#
For clinics
- Roles for owners, administrators, providers, staff and billing, so each person sees only what their job needs.
- Multi-factor authentication for every account, and single sign-on with Google Workspace.
- Automatic sign-out after a period of inactivity, which the clinic can shorten.
- Immediate removal of access when an administrator removes a staff member, including any open sessions.
- A record of every sign-in, with the device and browser used, visible to the clinic's administrators.
Inside Modulon
- Access to production systems is limited to a small number of engineers who need it, requires multi-factor authentication on managed devices, is granted for a limited time, and is logged.
- Our team looks at a clinic's data only to provide support the clinic has asked for, or to keep the service secure, and every such access is recorded.
- Access rights are reviewed every quarter and removed on the day someone leaves the company.
- Company laptops are encrypted, centrally managed and kept up to date. PHI is never stored on them, or on any personal device.
06Our people#
- Background checks for everyone who joins Modulon before they are given access to customer data.
- A confidentiality agreement signed by every employee and contractor.
- Security and HIPAA training when they join and every year after, with phishing exercises during the year.
- A sanctions policy for anyone who breaks our security or privacy policies.
07AI safeguards#
Rules the AI cannot override
- Clinic policies, such as which visit types can be booked, how many new patients a provider sees in a day, and when patients may be texted, are enforced in software. The AI is not asked to remember them; it cannot act outside them.
- When a request falls outside a clinic's policies, the AI hands it to staff rather than guessing.
- Nothing clinical, such as results, refills or advice, reaches a patient without a clinician's approval.
Accountability
- Every action the AI takes is recorded with the rule that allowed it, so staff can review and correct it.
- New tasks run in a watch-only mode first, drafting what the AI would do without sending anything, until the clinic turns them on.
- Callers and texters are told they are talking to an automated assistant, and can ask for a person at any time.
Model providers
- Our AI providers are bound by Business Associate Agreements, retain no PHI, and do not use it to train their models.
- Each request carries only the information that task needs.
- We test the AI against known misuse, such as attempts to talk it out of a rule or to extract another patient's information, before each release.
08Audit trail#
Modulon keeps a complete record of every action in the platform, whether taken by staff or by the AI: who or what took it, when, on which record, and why. The trail cannot be edited, is kept for at least six years, and can be reviewed and exported by clinic administrators at any time. It supports the clinic's own HIPAA audits and accountings of disclosures.
09Integrations#
- Connections to a clinic's record system, phone system, inbox and other tools are granted by a clinic administrator and use the narrowest access each feature needs.
- Integration credentials are encrypted and kept in a dedicated secret store.
- A clinic can see what each connection reads and writes, and disconnect it at any time.
- Data that Modulon writes back to the record system is recorded in the audit trail like any other action.
10Calls, texts and email#
- Calls and texts are carried by our telephony provider under a Business Associate Agreement, and call recordings and transcripts are stored encrypted with the rest of the clinic's data.
- Patient text messages avoid clinical detail where they can, and link to a secure page for anything sensitive.
- Emails the platform sends to clinic staff carry no PHI; they link back into the platform, where staff sign in to see the detail.
11Payments#
Patient payments are processed by Stripe, a PCI DSS Level 1 certified payment processor, and paid out directly to the clinic's own account. Card details are entered on Stripe's secure fields and never touch Modulon's servers. Payments carry no clinical information.
12Secure development#
- Every code change is reviewed by another engineer and tested automatically before it reaches production.
- Code and dependencies are scanned for known vulnerabilities, and fixes are applied on a set timetable.
- Production systems are monitored around the clock, and alerts reach the on-call engineer within minutes.
- Infrastructure is scanned for vulnerabilities at least every six months, and an independent firm tests the platform every year.
13Incident response#
We maintain a written incident response plan and rehearse it every year. If an incident affects a clinic's data, we:
- Contain it, preserve the evidence and investigate the cause.
- Notify the clinic without undue delay: within 48 hours of a personal data breach under our Data Processing Agreement, and no later than ten business days after discovering a breach of unsecured PHI under our Business Associate Agreement.
- Keep the clinic informed as we investigate, and give it what it needs to notify patients and regulators.
- Fix the cause, and review what happened so it does not happen again.
Service availability is published on our status page.
14Reporting a vulnerability#
If you believe you have found a security vulnerability in Modulon, please report it to hello@modulonhealth.com. Include enough detail for us to reproduce it. We will acknowledge your report within two business days and keep you updated as we fix it.
We will not pursue legal action against researchers who act in good faith: who avoid accessing or changing patient data, do not disrupt the service, do not use social engineering or physical attacks, and give us reasonable time to fix the problem before disclosing it.
15Security documentation#
Clinics evaluating Modulon can request our Business Associate Agreement or Data Processing Agreement, a completed security questionnaire, a summary of our latest risk analysis and independent testing, and details of our subprocessors by writing to hello@modulonhealth.com. We reply within two business days.
Questions about this page? Write to hello@modulonhealth.com.