Home

Trust Center

This page is maintained by My Health Passport to answer common security and privacy questions. It describes the safeguards enabled today; it is not an independent certification.

Compliance frameworks

  • HIPAA — aligned. Administrative, physical, and technical safeguards implemented; Business Associate Agreements in place with subprocessors handling PHI.
  • SOC 2 Type II — in progress. Continuous control monitoring live; observation window underway.
  • ISO 27001 — on roadmap. ISMS scope, risk register, policies, and Annex A control mapping maintained internally.
  • GDPR / UK GDPR — aligned. Records of processing, data subject rights workflow, DPA available on request.
  • HITRUST CSF — evaluation planned for enterprise health customers.

Status reflects internal readiness; independent audit reports available under NDA.

Infrastructure & subprocessors

  • Hosted on SOC 2 / ISO 27001–certified cloud infrastructure.
  • Managed Postgres with automated encrypted backups and point-in-time recovery.
  • AI processing routed through a controlled gateway with PHI scrubbing and no training on customer data.
  • Full subprocessor list on the Subprocessors page.

Retention, backup & continuity

  • Data retained per user-configurable retention policies; deleted records are purged from primary storage on schedule.
  • Encrypted backups tested on a rolling basis; documented RTO and RPO targets.
  • Incident response runbook with tabletop exercises; 72-hour breach notification commitment where legally required.

Organizational safeguards

  • Annual security & HIPAA training for all personnel with access to production.
  • Quarterly access reviews; least-privilege by default; break-glass elevation is logged and reviewed.
  • Vendor risk assessments on onboarding and at least annually thereafter.
  • Signed policies covering information security, access control, incident response, BCP/DR, vendor management, and acceptable use.

Access & authentication

  • Email/password and Google sign-in.
  • Role-based access (patient, practitioner, manufacturer, admin) enforced by row-level security.
  • Configurable session inactivity timeout with re-authentication before Export and Tap-to-share.
  • Optional MFA-required flag per account.

Data protection

  • All traffic is HTTPS/TLS.
  • Database encryption at rest is provided by our hosting platform.
  • Additional application-layer AES-256-GCM encryption for the most sensitive PHI fields (date of birth, diagnoses, free-text notes).
  • Automatic PHI scrubbing in logs, error traces, and AI agent inputs/outputs.

Auditability

  • Unified PHI access log covering reads, writes, exports, shares, and handoffs.
  • Immutable audit trail for share-token use and practitioner activity.
  • Anomaly detection for bulk exports, off-hours access, repeated failures, and wide practitioner sweeps.

Your rights

  • Download a complete copy of your data at any time.
  • Request permanent account and data deletion from Account & data.
  • Revoke any active share link from your profile.

Incidents & disclosures

Suspected security issues or privacy concerns can be reported tosecurity@myhealth.app. We will acknowledge reports within one business day.