TRUST & SECURITY

Security you can hand to your auditor.

Every Tessic Health clinic runs on infrastructure built for auditors as much as for patients: SOC 2 Type II certified, HIPAA compliant, EPCS ready, and structured so the client owns the data outright.

SOC 2

Type II, audited annually

HIPAA

BAAs with every client

EPCS

DEA-compliant prescribing

99.9%

Uptime SLA on Scale

CERTIFICATIONS & CONTROLS

Audited, certified, and built to stay that way.

Four control surfaces — independently verified where a framework exists, contractually guaranteed where one doesn't.

SOC 2

Certification

SOC 2 Type II

An independent auditor examines our security, availability, and confidentiality controls every year, across months of live operation rather than a single day. Reports are available to clients and qualified prospects under NDA.

HIPAA

Compliance

HIPAA

We sign a Business Associate Agreement with every client before any PHI moves. Handling, storage, and access to patient data follow the Privacy and Security Rules across every clinic we operate — the same standard on every plan.

EPCS

Prescribing

EPCS

DEA-compliant electronic prescribing of controlled substances: identity-proofed prescribers, two-factor signing on every controlled script, and prescription records retained to federal requirements.

SSO

Enterprise

Enterprise controls

The Scale program adds SSO / SAML, a 99.9% uptime SLA, and exportable audit logs — the controls enterprise security reviews ask for, in place before they ask.

DATA OWNERSHIP

Your patients. Your records. Your data.

Every clinic we stand up belongs to the client who launched it. The brand, the legal entity, the patient relationships, and every record generated inside them are the client's property. Tessic operates the infrastructure — that is all we claim.

Export runs on your schedule, not ours. Patient records, prescription history, and operational data are portable at any time, in standard formats, without a support ticket or an exit negotiation.

And if you ever leave, everything leaves with you. Patients, records, data, and the entity itself transfer out intact — no copies retained beyond what law requires, no wind-down fees, no hostage terms.

PATIENTSRECORDSDATAREVENUE— YOURS.

INFRASTRUCTURE PRACTICES

The controls running under every clinic.

Eight practices, applied uniformly. There is no premium tier for security basics.

01

Encryption in transit and at rest

TLS 1.2+ on every connection; AES-256 on every stored record. No plaintext PHI, anywhere, ever.

02

Least-privilege access

Access is scoped to role and reviewed quarterly. Production entry requires hardware-key MFA — no shared credentials, no standing admin rights.

03

Environment isolation

Production, staging, and development run fully separated. Scale clients get dedicated sandbox environments that never touch live PHI.

04

Continuous monitoring

Infrastructure and application telemetry watched around the clock, with anomaly alerts routed to an on-call engineer within minutes.

05

Third-party penetration testing

Independent security firms test the platform annually and after major architectural changes. Findings are triaged and fixed on committed timelines.

06

Vendor risk review

Every subprocessor that could touch PHI is assessed before onboarding and re-reviewed each year. The current list is available to clients on request.

07

Immutable audit logging

Every access to patient data is written to append-only logs that no one — including us — can edit or delete.

08

Incident response

A documented response plan with named owners, rehearsed regularly, and client notification SLAs written into every agreement.

LEGAL STRUCTURE

MSO + friendly-PC: the structure that keeps clinics compliant.

Most states prohibit corporations from practicing medicine. The compliant pattern separates the two concerns: a professional corporation — the "friendly PC," owned by licensed physicians — employs the providers and delivers care, while a management services organization (the MSO) runs everything non-clinical: technology, billing, marketing, and operations. Clinical judgment stays with clinicians; business operations stay with the business.

Tessic drafts this structure for every clinic we stand up, with the client's ownership written in from the first document. The boundary between clinical practice and business operations is contractual, auditable, and built to survive regulatory scrutiny — which means the clinic you launch this quarter is still standing, and still yours, years from now.

SECURITY FAQ

The questions security reviews ask.

Short answers here. Full documentation, audit reports, and BAAs are available to clients and qualified prospects under NDA.

  • Your clinic does. PHI generated in a Tessic-operated clinic belongs to your entity, held under the friendly-PC structure drafted for your ownership. Tessic processes it as a business associate — we never claim ownership, and it is portable at any time.

  • We execute a Business Associate Agreement with every client before any PHI is created or transferred. It defines permitted uses, required safeguards, breach notification timelines, and the return or destruction of data at termination. Our subprocessors are bound by equivalent downstream agreements.

  • In access-controlled United States data centers, encrypted at rest with AES-256 and replicated across availability zones for durability. Patient data does not leave the US, and Scale sandbox environments are isolated from production PHI entirely.

  • Email security@tessichealth.com with reproduction steps. We acknowledge reports within one business day, keep you informed through remediation, and do not pursue action against good-faith research.

  • Through EPCS — the DEA's framework for electronic controlled-substance prescribing. Prescribers complete identity proofing, every controlled script requires two-factor signing, and prescription records are retained and auditable. State-level requirements such as PDMP checks are enforced inside the prescribing workflow.

Responsible disclosure: we welcome good-faith security research and will not pursue action against it. Report findings to security@tessichealth.com — we acknowledge every report within one business day.