Trust and security

Your patients' records, held to the standard you would hold them to.

Qintara is built by a working hormone optimization practice. The controls below are the ones we rely on for our own patients every day, not a list assembled for a sales page.

How the platform protects PHI

Four controls do most of the work. Each one is enforced by the platform, not by policy or training.

Encrypted with keys held per practice

Patient data is encrypted at rest using AWS Key Management Service, with a separate key for each practice. One clinic's key cannot open another clinic's records.

Isolation enforced in the database

Row-level security runs inside the database itself, so a query can only ever return the practice it belongs to. It holds even if the application layer is wrong.

Identity and single sign-on

Authentication runs on AWS Cognito with multi-factor authentication and role-based permissions. Practices on Microsoft can federate their own directory and keep their existing sign-in.

An audit trail that cannot be edited

Administrative actions are written to an append-only log, and records are retired rather than destroyed, so the history of a chart stays intact.

Compliance posture

Where each item genuinely stands today. We would rather show you an honest date than a badge.

HIPAA

Business Associate Agreement signed with every practice before any patient data is loaded.

In force

SOC 2 Type I

Controls monitored continuously through Vanta. Audit window opens October 2026.

In progress

Encryption in transit and at rest

TLS on every connection, customer-managed keys on stored data.

In force

Web application firewall

Managed rules enforced at the edge on all patient-facing traffic.

In force

Subprocessor register

Every vendor that may handle PHI on your behalf is named, with an agreement in place. Available on request.

Maintained

Privacy

The short version, in plain terms.

Your patients' data is yours

Protected health information belongs to your practice. We process it only to provide the service you have engaged us for, under the terms of our Business Associate Agreement.

We do not sell it

We do not sell, rent or trade patient information, and we do not use it to advertise to you or to anyone else.

You can take it with you

Your records are exportable. Leaving does not mean losing your history.

Our full privacy notice and Business Associate Agreement are provided during onboarding and are available beforehand on request.

Questions before you commit?

Ask for the Business Associate Agreement, the subprocessor register, or a security review. A person answers.

(850) 842-6692
Monday to Friday, 9am to 6pm Central