Security and Compliance Built Into Every Layer

Moonshot Clinic is built from the ground up for HIPAA compliance. We don't bolt security on as an afterthought -- it's in the architecture.

HIPAA BAA Included AES-256 Multi-AZ EPCS Enabled

Authentication

Every authentication mechanism is designed to prevent credential theft, session hijacking, and unauthorized access -- not just check a compliance box.

Data Isolation

Every clinic's data is isolated at the database level. There is no configuration that allows one tenant to access another's records -- the database enforces this, not application code.

Encryption

Data is encrypted everywhere it exists -- at rest, in transit, and at the field level for the most sensitive identifiers.

Audit Logging

Every clinical action, login attempt, and record access is logged to an immutable audit trail. This is not optional and cannot be disabled.

Business Associate Agreement

Every plan includes a BAA. No upgrade required, no sales call, no waiting period.

Download our BAA immediately -- no form, no email gate. BAA signing is built into the onboarding wizard so you're covered from the moment you create your account.

Sign BAA During Registration

Infrastructure

The entire stack runs on AWS with redundancy, automated failover, and continuous monitoring.

Rate Limiting

API abuse, credential stuffing, and brute-force attacks are stopped before they reach your data.

Data Portability

Your data is yours. Full patient data export is available at any time through Settings. No lock-in, no export fees, no data hostage.

If you cancel your account, your data remains accessible for 90 days so you can complete your migration on your schedule. After that, it's securely deleted per HIPAA requirements.

Compliance Certifications

We don't just say we're compliant. Here's where we stand on every relevant standard.

🏥

HIPAA Compliant

BAA provided on all plans

Active
📝

Surescripts Network

E-prescribing via our certified ScriptSure integration

Active
🔒

EPCS Enabled

DEA-compliant controlled substances

Active
💳

Stripe PCI-DSS

Level 1 payment security

Active
🛡

SOC 2-Aligned Controls

Built to SOC 2 standards

Audit on Roadmap

Security & Compliance FAQ

Is Moonshot Clinic HIPAA compliant?
Yes. HIPAA compliance is built into the architecture: row-level security isolates every tenant's data at the database layer, all PHI is encrypted with AES-256 at rest and TLS in transit, and every access is audit-logged with logs retained for a minimum of 6 years.
Do I get a Business Associate Agreement (BAA)?
Every plan includes a BAA — no upgrade, no sales call, no waiting period. BAA signing is built into the onboarding wizard, so you're covered from the moment you create your account.
Where is my clinic's data stored?
In AWS data centers on multi-AZ PostgreSQL with automated failover. Data is encrypted with AES-256 at rest and TLS in transit, and tenant isolation is enforced with database row-level security — not just application code.
Is Moonshot Clinic SOC 2 certified?
Our controls are built to SOC 2 standards, and a formal SOC 2 audit is on the roadmap. Today we operate under HIPAA with a BAA on every plan, e-prescribing via ScriptSure, a Surescripts-certified EPCS application, DEA-compliant EPCS, and Stripe PCI-DSS Level 1 payments.
Can I export my data if I leave?
Yes. Full patient data export is available anytime through Settings — no export fees, no lock-in. After cancellation your data stays accessible for 90 days so you can migrate on your schedule, then it's securely deleted per HIPAA requirements.

Your patients' data deserves better than "good enough."

Get started with full HIPAA compliance from day one. BAA included with every plan.