carelinkMD Security & Compliance
carelinkMD is committed to maintaining strong administrative, technical, and physical safeguards to protect customer data, including Protected Health Information ("PHI").
This page provides an overview of our security and compliance practices.
Compliance Framework
carelinkMD security practices are designed to align with:
- HIPAA Security Rule (45 CFR Part 164 Subpart C)
- HIPAA Privacy Rule (where applicable under Business Associate Agreements)
- SOC 2 Trust Services Criteria (Security, Availability, Confidentiality principles)
- Industry best practices for cloud-based healthcare SaaS platforms
carelinkMD is not currently SOC 2 certified unless explicitly stated in a signed agreement or updated documentation.
Data Hosting & Infrastructure
carelinkMD is hosted on Microsoft Azure, which provides enterprise-grade infrastructure including:
- Secure, physically protected data centers
- High availability and redundancy
- Network-level security controls and DDoS protection
- Continuous monitoring and threat detection
We leverage Azure security services such as:
- Identity and Access Management (Azure Active Directory)
- Key Management (Azure Key Vault)
- Cloud security monitoring tools (Microsoft Defender for Cloud)
Data Encryption
### In Transit
- All data transmitted between users and carelinkMD is encrypted using TLS 1.2 or higher
### At Rest
- All stored data, including PHI, is encrypted using AES-256 encryption standards
### Key Management
- Encryption keys are securely managed using industry-standard cloud key management systems
- Access to encryption keys is strictly controlled and logged
Access Control & Authentication
carelinkMD enforces strict access controls:
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA) for administrative access
- Least-privilege access principles
- Secure session management and automatic session timeouts
Only authorized personnel may access production systems containing PHI.
Data Segregation & Privacy Controls
- Customer data is logically separated in a multi-tenant architecture
- Access between tenants is strictly prohibited by system design
- PHI is only accessible to authorized users within the applicable healthcare organization
carelinkMD does not sell, rent, or use PHI for advertising or AI training.
Logging, Monitoring & Auditing
carelinkMD maintains system logs to monitor:
- Authentication activity
- Data access and modifications
- System and application events
- Security-relevant activities
Logs are:
- Continuously monitored for anomalies
- Protected from unauthorized access
- Retained for compliance and investigation purposes
Vulnerability Management
We maintain an ongoing security program that includes:
- Regular vulnerability scanning
- Dependency and third-party library monitoring
- Security patch management
- Internal security reviews and updates
Critical issues are prioritized and addressed promptly.
Incident Response & Breach Notification
carelinkMD maintains an incident response process to detect, respond to, and mitigate security incidents.
In the event of a confirmed security incident involving PHI:
- We will notify affected customers without unreasonable delay
- Notification will occur no later than 10 calendar days after discovery, unless otherwise required by law or agreement
- Notifications will include relevant details and remediation steps
Data Backup & Disaster Recovery
carelinkMD maintains business continuity protections including:
- Encrypted data backups
- Redundant system architecture
- Disaster recovery procedures designed to restore service in the event of failure
Backup systems are tested periodically to ensure reliability.
Subprocessors
carelinkMD may use trusted third-party service providers ("subprocessors"), including:
- Cloud infrastructure providers (e.g., Microsoft Azure)
- Security and monitoring service providers
All subprocessors are required to:
- Maintain appropriate security controls
- Protect confidentiality of data
- Comply with applicable legal and contractual obligations
A list of subprocessors may be provided upon request or via a Data Processing Addendum (DPA).
Employee Security
All carelinkMD personnel with access to systems handling sensitive data are subject to:
- Confidentiality obligations
- Security awareness training
- Background checks (where applicable)
- Role-based access restrictions
- Immediate access revocation upon termination
Customer Responsibilities
Customers (healthcare organizations) are responsible for:
- Maintaining secure credentials and access controls
- Configuring appropriate user permissions
- Ensuring compliance with HIPAA and applicable regulations
- Reporting suspected security incidents promptly
Compliance Documentation
Upon reasonable request, carelinkMD may provide:
- Security architecture overview
- HIPAA compliance documentation
- Subprocessor information
- Summary of technical safeguards
Enterprise customers may request additional documentation under separate agreements.
Limitations
While carelinkMD implements strong security controls, no system can guarantee absolute security.
Security depends on both:
- Platform safeguards
- Customer configuration and usage practices
Contact
For security or compliance inquiries:
carelinkMD
1200 Riverplace Blvd, Suite 105
Jacksonville, FL 32207
Email: legal@carelinkmd.com