Security & Data Protection
Your credentialing data is sensitive. CREDSClinic is built from the ground up with healthcare-grade security — HIPAA-compliant, encrypted, and independently audited.
Encryption at Rest & in Transit
All protected health information (PHI) is encrypted at rest using AES-256 and in transit using TLS 1.3. Data is never stored or transmitted in plaintext.
Microsoft Azure HIPAA Infrastructure
Hosted on Microsoft Azure HIPAA-eligible services. A signed Business Associate Agreement (BAA) is in place, providing enterprise-grade compliance controls and data residency guarantees.
Role-Based Access Controls
Granular role-based permissions ensure that only authorized personnel can access sensitive provider data. Every access event is audit-logged with timestamps and IP addresses.
Annual Third-Party Audits
We conduct annual third-party security assessments and continuous vulnerability monitoring to maintain a strong compliance posture and rapidly address emerging threats.
Data Minimization
We collect only the data necessary for credentialing. Provider data is not sold to or shared with third parties except as required by credentialing submissions.
Breach Notification
In the unlikely event of a data breach, CREDSClinic follows HIPAA-mandated breach notification procedures, including timely notification to affected individuals and HHS.
HIPAA Compliance Details
For full information on our HIPAA safeguards, BAA terms, and compliance controls, see our dedicated HIPAA page.
View HIPAA Compliance PageHave a security concern or vulnerability to report? Contact our security team