Security and HIPAA

We are your business associate. We act like it.

Attergo handles protected health information under a signed business associate agreement, executed before a single event is accepted. Below is how the product is built, control by control, and we will walk your reviewer through any of them.

Attergo: the audit case list, showing open PBM audits with their deadlines and the evidence gathered against each.

Tenancy

Two controls, both sitting below the application layer.

  • Isolation enforced in the data layer, not in application code. An application bug cannot cross a tenant boundary.
  • Per-location ingestion credentials, rotatable by you without contacting us.

Access

Who can reach patient data, and the record of every time they did.

  • Five roles: Owner, Pharmacist, Technician, Billing, Read-only. Least privilege by default.
  • Time-based two-factor required on every account, including ours.
  • Every read of PHI is written to an append-only access log the pharmacy can inspect and export.
  • Support staff need a named, time-boxed grant to view a tenant's data, and the grant appears in your log.

Data

In transit, at rest, and in the places data is never allowed to appear.

  • In transit, TLS 1.2 or better everywhere.
  • At rest, connector credentials and authenticator secrets are encrypted with AES-256-GCM under per-tenant keys derived from a master key. Volume-level encryption of the database and the object store is not in place.
  • Documents and prescription images held in encrypted object storage with per-tenant keys.
  • Raw event archive is append-only and retained ten years for audit defence.
  • No PHI in application logs, error messages, URLs or analytics. Automated tests fail the build if a PHI-marked field reaches a log statement.

Retention and residency

How long we hold it, where it sits, and what leaves with you.

  • Raw event archive, documents and access log: ten years, write-once.
  • Application logs: 90 days, no PHI.
  • Data residency: United States only.
  • On termination you receive a full export of the raw archive and every document you uploaded, readable without us.

Subprocessors

The register is published, not supplied on request: it names every party that can reach anything, states whether that includes protected health information, and says where it processes. Its date changes when the register does. No party receives customer data before it is engaged under a written agreement imposing obligations no weaker than the ones we owe you.

Incident response

Contractual notification timelines, a named contact, and an incident report you can hand to your own counsel. Component-level status and 90 days of incident history are public at status.attergo.com, with the marketing site, the application and the API each reported separately.

Attestation

A business associate agreement is executed per pharmacy before a single event is accepted, and it is published in full rather than sent on request.

SOC 2 Type II controls are documented. The audit has not yet begun.

For your reviewer

Our position under the Rules HIPAA compliance
Who else can touch the data Sub-processor register
What you hold and how you export it Data and export
Reporting a security issue Disclosure policy
Security contact security@attergo.com

Connect one store. We will tell you what the month cost you.

Read-only credentials you can revoke. We come back with the fills that went out under cost, the services you could have billed, and the fills an auditor would ask about.