TRUST & SECURITY
Security you can hand to your auditor.
Every Tessic Health clinic runs on infrastructure built for auditors as much as for patients: SOC 2 Type II certified, HIPAA compliant, EPCS ready, and structured so the client owns the data outright.
SOC 2
Type II, audited annually
HIPAA
BAAs with every client
EPCS
DEA-compliant prescribing
99.9%
Uptime SLA on Scale
CERTIFICATIONS & CONTROLS
Audited, certified, and built to stay that way.
Four control surfaces — independently verified where a framework exists, contractually guaranteed where one doesn't.
Certification
SOC 2 Type II
An independent auditor examines our security, availability, and confidentiality controls every year, across months of live operation rather than a single day. Reports are available to clients and qualified prospects under NDA.
Compliance
HIPAA
We sign a Business Associate Agreement with every client before any PHI moves. Handling, storage, and access to patient data follow the Privacy and Security Rules across every clinic we operate — the same standard on every plan.
Prescribing
EPCS
DEA-compliant electronic prescribing of controlled substances: identity-proofed prescribers, two-factor signing on every controlled script, and prescription records retained to federal requirements.
Enterprise
Enterprise controls
The Scale program adds SSO / SAML, a 99.9% uptime SLA, and exportable audit logs — the controls enterprise security reviews ask for, in place before they ask.
DATA OWNERSHIP
Your patients. Your records. Your data.
Every clinic we stand up belongs to the client who launched it. The brand, the legal entity, the patient relationships, and every record generated inside them are the client's property. Tessic operates the infrastructure — that is all we claim.
Export runs on your schedule, not ours. Patient records, prescription history, and operational data are portable at any time, in standard formats, without a support ticket or an exit negotiation.
And if you ever leave, everything leaves with you. Patients, records, data, and the entity itself transfer out intact — no copies retained beyond what law requires, no wind-down fees, no hostage terms.
INFRASTRUCTURE PRACTICES
The controls running under every clinic.
Eight practices, applied uniformly. There is no premium tier for security basics.
01
Encryption in transit and at rest
TLS 1.2+ on every connection; AES-256 on every stored record. No plaintext PHI, anywhere, ever.
02
Least-privilege access
Access is scoped to role and reviewed quarterly. Production entry requires hardware-key MFA — no shared credentials, no standing admin rights.
03
Environment isolation
Production, staging, and development run fully separated. Scale clients get dedicated sandbox environments that never touch live PHI.
04
Continuous monitoring
Infrastructure and application telemetry watched around the clock, with anomaly alerts routed to an on-call engineer within minutes.
05
Third-party penetration testing
Independent security firms test the platform annually and after major architectural changes. Findings are triaged and fixed on committed timelines.
06
Vendor risk review
Every subprocessor that could touch PHI is assessed before onboarding and re-reviewed each year. The current list is available to clients on request.
07
Immutable audit logging
Every access to patient data is written to append-only logs that no one — including us — can edit or delete.
08
Incident response
A documented response plan with named owners, rehearsed regularly, and client notification SLAs written into every agreement.
LEGAL STRUCTURE
MSO + friendly-PC: the structure that keeps clinics compliant.
Most states prohibit corporations from practicing medicine. The compliant pattern separates the two concerns: a professional corporation — the "friendly PC," owned by licensed physicians — employs the providers and delivers care, while a management services organization (the MSO) runs everything non-clinical: technology, billing, marketing, and operations. Clinical judgment stays with clinicians; business operations stay with the business.
Tessic drafts this structure for every clinic we stand up, with the client's ownership written in from the first document. The boundary between clinical practice and business operations is contractual, auditable, and built to survive regulatory scrutiny — which means the clinic you launch this quarter is still standing, and still yours, years from now.
SECURITY FAQ
The questions security reviews ask.
Short answers here. Full documentation, audit reports, and BAAs are available to clients and qualified prospects under NDA.
Your clinic does. PHI generated in a Tessic-operated clinic belongs to your entity, held under the friendly-PC structure drafted for your ownership. Tessic processes it as a business associate — we never claim ownership, and it is portable at any time.
We execute a Business Associate Agreement with every client before any PHI is created or transferred. It defines permitted uses, required safeguards, breach notification timelines, and the return or destruction of data at termination. Our subprocessors are bound by equivalent downstream agreements.
In access-controlled United States data centers, encrypted at rest with AES-256 and replicated across availability zones for durability. Patient data does not leave the US, and Scale sandbox environments are isolated from production PHI entirely.
Email security@tessichealth.com with reproduction steps. We acknowledge reports within one business day, keep you informed through remediation, and do not pursue action against good-faith research.
Through EPCS — the DEA's framework for electronic controlled-substance prescribing. Prescribers complete identity proofing, every controlled script requires two-factor signing, and prescription records are retained and auditable. State-level requirements such as PDMP checks are enforced inside the prescribing workflow.
Responsible disclosure: we welcome good-faith security research and will not pursue action against it. Report findings to security@tessichealth.com — we acknowledge every report within one business day.